HelloNet Campaign Abuses ViPNet Updates to Target Russian Government Agencies
A sophisticated threat actor, dubbed HelloNet, is leveraging the update mechanism of **ViPNet** private networking software to compromise high-value Russian organizations, including government entities. The campaign, active since May, deploys a multi-stage malware payload designed for proxying, command execution, and stealthy network reconnaissance.
An advanced threat actor is abusing the update mechanism for the **ViPNet** private networking product suite to target Russian organizations, including government agencies.
Dubbed **HelloNet**, the campaign has been active since at least May, deploying a malicious payload that acts as a proxy and loader for additional malware.
According to **Kaspersky** researchers, **HelloNet** has impacted organizations in the government, energy, transport, education, and logistics sectors.
### ViPNet Update Abuse
**ViPNet** is a family of Russian information-security products developed by **InfoTeCS**, providing VPN, endpoint, and network access protection, firewall, certificate management, centralized administration, and secure messaging and file transfer.
The tool is commonly used in Russia, where it is certified by the authorities for use in government and other regulated environments.
Due to its market reach in Russia, especially among high-value organizations, it has been targeted often by hackers. In April 2025, **Kaspersky** reported that threat actors impersonated a **ViPNet** update in attacks.
In the latest campaign, attackers placed a malicious file (`wtsapi32.dll`, dubbed **HelloInjector**) inside the local **ViPNet** Update System directory to be sideloaded at system startup via the legitimate `itcsrvup64.exe`.
This DLL is the first-stage loader that injects into the `svchost.exe` process, granting next-stage payloads elevated privileges on **Windows** and persistence across reboots.
**Kaspersky** does not describe exactly how the attackers gained initial access to perform this file change, nor do they claim that **ViPNet**βs update infrastructure itself was compromised.
### Malware Toolset
**HelloInjector** runs its embedded payload, which **Kaspersky** named **HelloProxy**, in memory and contacts the command-and-control (C2) server to receive additional modules.
One of these modules is **HelloExecutor**, a backdoor that can execute commands and conduct network reconnaissance on the host.
A second one is **HelloCleaner**, a tool that removes **ViPNet** log data to hide the malicious activity.
Another implant called **HelloBackdoor** is **Rust**-based and supports uploading and downloading files, as well as command execution.
**Kaspersky** has tentatively attributed the campaign to an unidentified Chinese-speaking advanced persistent threat (APT) group.
However, the researchers stressed that the evidence is weak, relying primarily on an unused string referencing the Chinese website sina.com and a malware download mirror hosted by the **University of Science and Technology of China**.
As a result, they assign the attribution low confidence and do not rule out the possibility of a false flag operation.
The cybersecurity firm recommends thorough monitoring of systems running **ViPNet** software, particularly traffic passing through ports 5003, 5060 (**HelloProxy**), and 443 (**HelloBackdoor**).