An advanced threat actor is abusing the update mechanism for a widely used Russian networking product to deliver a multi-stage proxy and loader to government and other high-value organizations, according to Kaspersky researchers.
HelloNet campaign and the organizations hit
Kaspersky has named the campaign HelloNet and says it has been active since at least May. The firm reports impacts to organizations in Russia across government, energy, transport, education, and logistics sectors. The deployed payload acts as both a proxy and a loader for follow-on modules, enabling attackers to maintain footholds and move laterally.
How attackers abused ViPNet update files
The intrusion leverages ViPNet, a family of information-security products developed by InfoTeCS that provides VPN, endpoint and network protection, certificate management, centralized administration, and secure messaging and file transfer. ViPNet is commonly used in Russia and is certified by the authorities for government and other regulated environments — factors Kaspersky notes make it a high-value target.
In the HelloNet attacks, adversaries placed a malicious DLL file, wtsapi32.dll (which Kaspersky dubs HelloInjector), inside the local ViPNet Update System directory so it would be sideloaded at system startup by the legitimate itcsrvup64.exe process. HelloInjector is described as a first-stage loader that injects into the svchost.exe process, delivering elevated privileges and persistence across reboots.
Kaspersky explicitly states it does not describe exactly how the attackers gained the initial access needed to overwrite that update-directory file, and the researchers do not claim that ViPNet’s update infrastructure itself was compromised.
Modular malware toolset observed by Kaspersky
Kaspersky’s analysis details a set of modules delivered via the HelloInjector chain. HelloInjector runs an embedded payload, HelloProxy, in memory and connects to a command-and-control server to receive additional components. The named modules include:
- HelloExecutor — a backdoor capable of executing commands and performing network reconnaissance on the host.
- HelloCleaner — a utility that removes ViPNet log data to conceal malicious activity.
- HelloBackdoor — a Rust-based implant that supports uploading and downloading files as well as command execution.
The researchers recommend monitoring systems running ViPNet and paying particular attention to traffic on ports 5003 and 5060 (associated with HelloProxy) and port 443 (associated with HelloBackdoor).
Kaspersky’s attribution and its limits
Kaspersky has tentatively attributed HelloNet to an unidentified Chinese-speaking advanced persistent threat (APT) group, but the firm assigns that attribution low confidence. The attribution rests primarily on an unused string referencing the Chinese website sina.com and a malware download mirror hosted by the University of Science and Technology of China. Kaspersky warns these indicators are weak and does not rule out the possibility of a false flag operation.
What this means for technologists, procurement leaders, and affected enterprises
- Technologists and security teams: Kaspersky recommends thorough monitoring of ViPNet installations and network traffic on ports 5003, 5060, and 443. Teams should look for unexpected files in the ViPNet Update System directory, processes invoking itcsrvup64.exe, and signs of DLL sideloading and svchost.exe injection. The presence of tools that delete ViPNet logs (HelloCleaner) increases the need for immutable or remote logging where possible.
- Procurement leaders and administrators of regulated systems: Because ViPNet is certified and widely deployed in government and regulated environments, procurement and risk teams should review assumptions about update-file integrity and ask vendors about protections around local update directories and the update process.
- Affected enterprises (government, energy, transport, education, logistics): Organizations in these sectors should treat any unexplained ViPNet anomalies as high priority, given the campaign’s targeting and the malware’s capability to execute commands, move laterally, and erase local logs.
Two practical follow-ups stand out from Kaspersky’s account: investigators still do not know how attackers first wrote the malicious wtsapi32.dll into the ViPNet update directory, and the low-confidence attribution leaves open who is responsible — or whether the visible Chinese-language artefacts are intended to mislead. In the near term, the actionable fact is straightforward: systems running ViPNet require tighter monitoring of update paths, process behavior around itcsrvup64.exe and svchost.exe, and traffic on the ports Kaspersky highlights.
For the original reporting, see Hackers abuse ViPNet software to target Russian govt agencies — BleepingComputer.




