HelloNet Campaign Targets Russian Government via ViPNet Software Exploitation

HelloNet Campaign Targets Russian Government via ViPNet Software Exploitation

First seen 19 Jul 2026, 16:46 UTC Bleepingcomputersecurelist.comwww.tines.com 82% similarity 75.0

Article Content

Browse articles
ThreatCluster

An advanced threat actor, identified as HelloNet, is exploiting the ViPNet software update mechanism to target Russian government agencies and other sectors. The campaign has been active since May 2026, deploying a malicious payload that acts as a proxy and loader for additional malware. Kaspersky researchers report that organizations in government, energy, transport, education, and logistics have been affected. The attackers sideloaded a malicious DLL (wtsapi32.dll) into the ViPNet Update System directory, allowing it to run at system startup. This DLL serves as a loader for further malicious payloads, including a backdoor named HelloExecutor and a tool named HelloCleaner that erases log data. Kaspersky has tentatively attributed the campaign to an unidentified Chinese-speaking APT group but noted low confidence in this attribution. Security teams are advised to monitor traffic on specific ports associated with the malicious payloads. The ViPNet software is widely used in Russia and has been targeted previously by hackers.

Key Points: • HelloNet campaign exploits ViPNet software to target Russian government and sectors. • Malicious payloads include backdoors and tools for network reconnaissance and log deletion. • Kaspersky attributes the attack to a Chinese-speaking APT group with low confidence.

ThreatCluster AI

Timeline

2025-04-01
Previous ViPNet attacks reported
Kaspersky reported earlier attacks where threat actors impersonated ViPNet updates, indicating ongoing targeting of the software.
BleepingComputer
2026-05-01
HelloNet campaign begins
The HelloNet campaign commenced, exploiting the ViPNet update mechanism to deploy malicious payloads across various sectors in Russia.
BleepingComputer
2026-07-19
Kaspersky publishes findings
Kaspersky released details on the HelloNet campaign, revealing its methods and impact on Russian organizations.
securelist.com

Community

Browse all →