A new campaign involving ViPNet update abuse has targeted Russian government agencies and organisations in the energy, transport, education, and logistics sectors.
Researchers have named the campaign HelloNet. It has reportedly been active since at least May and uses a malicious component that hides inside a legitimate ViPNet software directory.
The attackers do not appear to have compromised ViPNet’s official update infrastructure. Instead, they allegedly altered files on already compromised systems to misuse the trusted software during startup.
Attackers Abuse Trusted ViPNet Software
ViPNet is a Russian suite of security products used for virtual private networks, endpoint protection, firewall controls, certificate management, secure messaging, and file transfers.
It is widely deployed in Russia, particularly by government bodies and regulated organisations. Consequently, it is an attractive target for threat actors seeking access to sensitive networks.
In the latest campaign, attackers reportedly placed a malicious dynamic-link library file inside the local ViPNet Update System folder. When the legitimate update executable runs, it loads the attacker-controlled file instead.
This technique is known as DLL side-loading. It allows malware to run through a trusted application, making malicious activity harder to detect.
HelloNet Malware Gains Persistent Access
The malicious file, which researchers call HelloInjector, acts as the first stage of the infection chain.
It reportedly injects malicious code into a Windows system process. This gives the attackers elevated access and helps the malware remain active after the system restarts.
The initial component then loads another in-memory payload called HelloProxy. This malware contacts an external command-and-control server and receives additional modules.
Researchers identified several tools in the HelloNet toolkit, including:
- HelloExecutor, a backdoor used to run commands and inspect the compromised network
- HelloCleaner, a component designed to remove ViPNet log data and hide the attackers’ activity
- HelloBackdoor, a Rust-based implant that can transfer files and execute commands
Together, these tools could allow attackers to maintain access, collect information, move through a network, and reduce the chances of detection.
Initial Access Method Remains Unknown
Researchers have not determined how the attackers initially gained access to the affected systems.
The file modification required for the ViPNet update abuse campaign would normally require prior access to a device. Therefore, the attack likely begins with another intrusion method before the malicious DLL is placed in the ViPNet directory.
Importantly, researchers have not said that ViPNet itself contains a vulnerability or that its central update servers were breached.
This distinction matters because the campaign appears to exploit trust in locally installed software rather than a confirmed flaw in the product’s update mechanism.
Possible Link to Chinese-Speaking Group
The campaign has been tentatively linked to an unidentified Chinese-speaking advanced persistent threat group.
However, the attribution remains weak. The available evidence includes an unused reference to a Chinese website and a malware download mirror hosted by a Chinese university.
Researchers have assigned low confidence to this assessment and warned that the clues could also be part of a false-flag effort.
As a result, the identity and motivation of the attackers remain unclear.
Organisations Should Monitor ViPNet Systems
The ViPNet update abuse campaign shows why trusted security software can become a valuable target. If attackers can alter files used by a legitimate program, they may bypass basic security controls and remain hidden for longer.
Organisations using ViPNet should review the integrity of files in their update directories and investigate unexpected changes. They should also monitor for unusual network connections, suspicious processes, and signs that security logs have been altered or deleted.
Finally, administrators should limit write access to software installation folders and ensure endpoint-protection tools can detect DLL side-loading behaviour.


0 responses to “ViPNet Update Abuse Targets Russian Government Agencies”