Hackers Exploit ViPNet Software to Target Russian Government Agencies

www.news4hackers.com-hackers-exploit-vipnet-software-to-target-russian-government-agencies-hackers-exploit-vipnet-software-to-target-russian-government-agencies

A sophisticated cyber threat group has leveraged the update mechanism of the ViPNet secure communication suite to infiltrate Russian organizations, including governmental institutions.

Attack Overview

The operation, attributed to a threat actor known as HelloNet, has been ongoing since at least May 2026. The campaign involves deploying a malicious payload that functions as a proxy and loader for additional malware, enabling persistent access and data exfiltration. Kaspersky researchers identified the campaign, noting its impact on entities across government, energy, transportation, education, and logistics sectors.

ViPNet and Attack Method

ViPNet, a Russian-developed security product line by InfoTeCS, provides virtual private networks, endpoint protection, firewall capabilities, and secure messaging. Its widespread use in Russia, particularly in regulated environments, makes it a prime target for adversaries. Attackers exploited the ViPNet Update System by embedding a malicious file, wtsapi32.dll, designated as HelloInjector, within the local update directory. This file is loaded at system startup through the legitimate itcsrvup64.exe process.

Malware Components

HelloInjector

The malicious DLL acts as a first-stage loader, injecting itself into the svchost.exe process to escalate privileges and maintain persistence after reboots.

HelloProxy

The malware toolkit includes HelloProxy, a memory-resident component that communicates with a command-and-control server to receive supplementary modules. One such module, HelloExecutor, serves as a backdoor capable of executing commands and conducting network reconnaissance.

HelloCleaner

Another tool, HelloCleaner, deletes ViPNet log files to obscure the intrusion. A Rust-based implant named HelloBackdoor facilitates file uploads and downloads, operating over port 443.

Attribution and Uncertainty

Kaspersky tentatively links the campaign to an unidentified Chinese-speaking advanced persistent threat group. However, the evidence remains inconclusive, relying on an unused string referencing the Chinese website sina.com and similarities in malware code. Researchers emphasize low confidence in this attribution, cautioning against potential false flag operations.

Recommendations

The firm advises organizations using ViPNet to monitor network traffic on ports 5003, 5060, and 443 for anomalies. Security teams are urged to conduct thorough system audits and implement strict access controls to mitigate risks associated with compromised update mechanisms.

Conclusion

The attack highlights the growing sophistication of state-sponsored cyber operations, where trusted software ecosystems are weaponized to bypass traditional security measures. As threat actors continue to exploit supply chain vulnerabilities, proactive defense strategies and continuous threat intelligence monitoring are critical to safeguarding sensitive infrastructure.



About Author

en_USEnglish