HelloNet Campaign Targets Russian Government via ViPNet Software Exploitation
ID: 0f64607d-8ff4-5301-bdf3-c22eaa494a8b
STIX ID: report--0f64607d-8ff4-5301-bdf3-c22eaa494a8b
Feed Name: ThreatCluster
Kaspersky researchers report an active HelloNet campaign (since May 2026) that compromises ViPNet's update system by sideloading a malicious wtsapi32.dll to achieve persistent execution, act as a loader/proxy, and deploy additional malware including the HelloExecutor backdoor and HelloCleaner log-deletion tool; targets include Russian government agencies and critical sectors (energy, transport, education, logistics), and defenders are advised to monitor related network ports while attribution to a Chinese-speaking APT remains low-confidence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
