logo

HelloNet Campaign Targets Russian Government via ViPNet Software Exploitation

ID: 0f64607d-8ff4-5301-bdf3-c22eaa494a8b

STIX ID: report--0f64607d-8ff4-5301-bdf3-c22eaa494a8b

Feed Name: ThreatCluster

Threat Score
82/100

Date Published: 2026-07-19

Date Updated: 2026-07-19

...
...

Kaspersky researchers report an active HelloNet campaign (since May 2026) that compromises ViPNet's update system by sideloading a malicious wtsapi32.dll to achieve persistent execution, act as a loader/proxy, and deploy additional malware including the HelloExecutor backdoor and HelloCleaner log-deletion tool; targets include Russian government agencies and critical sectors (energy, transport, education, logistics), and defenders are advised to monitor related network ports while attribution to a Chinese-speaking APT remains low-confidence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.