Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    IEEE Publishing Ethics Team Upholds Research Integrity

    July 30, 2026

    Why a Tiny Social Media Post Has Mathematicians Rethinking AI

    July 30, 2026

    Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic

    July 30, 2026
    Facebook X (Twitter) Instagram
    Trending
    • IEEE Publishing Ethics Team Upholds Research Integrity
    • Why a Tiny Social Media Post Has Mathematicians Rethinking AI
    • Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic
    • Montana’s plan to become an experimental medical hub just pushed forward
    • Detect the Signature of Dark Matter With a DIY Antenna
    • OpenAI’s Hacking Debacle Was a Human Mistake
    • The Download: tricking LLMs, and reviving geothermal plants
    • I Got a Free Meal From a Private Chef—Who Filmed It All to Train Robots
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Hackers abuse ViPNet software to target Russian govt agencies
    Cybersecurity

    Hackers abuse ViPNet software to target Russian govt agencies

    kirklandc008@gmail.comBy kirklandc008@gmail.comJuly 19, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Fake OpenAI repository on Hugging Face pushes infostealer malware
    Share
    Facebook Twitter LinkedIn Pinterest Email

    An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies.

    Dubbed HelloNet, the campaign has been active since at least May, deploying a malicious payload that acts as a proxy and loader for additional malware.

    According to Kaspersky researchers, HelloNet has impacted organizations in the government, energy, transport, education, and logistics sectors.

    ViPNet update abuse

    ViPNet is a family of Russian information-security products developed by InfoTeCS, providing VPN, endpoint, and network access protection, firewall, certificate management, centralized administration, and secure messaging and file transfer.

    The tool is commonly used in Russia, where it is certified by the authorities for use in government and other regulated environments.

    Due to its market reach in Russia, especially among high-value organizations, it has been targeted often by hackers. In April, 2025, Kaspersky reported that threat actors impersonated a ViPNet update in attacks.

    In the latest campaign, attackers placed a malicious file (wtsapi32.dll, dubbed HelloInjector) inside the local ViPNet Update System directory to be sideloaded at system startup via the legitimate itcsrvup64.exe.

    This DLL is the first-stage loader that injects into the svchost.exe process, granting next-stage payloads elevated privileges on Windows and persistence across reboots.

    Kaspersky does not describe exactly how the attackers gained initial access to perform this file change, nor do they claim that ViPNet’s update infrastructure itself was compromised.

    Malware toolset

    HelloInjector runs its embedded payload, which Kaspersky named HelloProxy, in memory and contacts the command-and-control (C2) server to receive additional modules.

    One of these modules is HelloExecutor, a backdoor that can execute commands and conduct network reconnaissance on the host.

    A second one is HelloCleaner, a tool that removes ViPNet log data to hide the malicious activity.

    Another implant called HelloBackdoor is Rust-based and supports uploading and downloading files, as well as command execution.

    Kaspersky has tentatively attributed the campaign to an unidentified Chinese-speaking advanced persistent threat (APT) group.

    However, the researchers stressed that the evidence is weak, relying primarily on an unused string referencing the Chinese website sina.com and a malware download mirror hosted by the University of Science and Technology of China.

    As a result, they assign the attribution low confidence and do not rule out the possibility of a false flag operation.

    The cybersecurity firm recommends thorough monitoring of systems running ViPNet software, particularly traffic passing through ports 5003, 5060 (HelloProxy), and 443 (HelloBackdoor).

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    abuse agencies govt hackers Russian software target ViPNet
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • IEEE Publishing Ethics Team Upholds Research Integrity
    • Why a Tiny Social Media Post Has Mathematicians Rethinking AI
    • Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic
    • Montana’s plan to become an experimental medical hub just pushed forward
    • Detect the Signature of Dark Matter With a DIY Antenna

    IEEE Publishing Ethics Team Upholds Research Integrity

    July 30, 2026

    Why a Tiny Social Media Post Has Mathematicians Rethinking AI

    July 30, 2026

    Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic

    July 30, 2026

    Montana’s plan to become an experimental medical hub just pushed forward

    July 30, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.