HelloNet campaign — new malicious modules launched through the ViPNet update system
ID: ffacbb96-9f9b-5f35-99b5-daeb0e26dd4b
STIX ID: report--ffacbb96-9f9b-5f35-99b5-daeb0e26dd4b
Feed Name: Securelist by Kaspersky
Date Published: 2026-07-16
Date Updated: 2026-07-23
Author: Konstantin Isakov, Georgy Kucherin, Anton Kargin
Kaspersky documents an active, targeted APT campaign (since at least May 2026) that compromises ViPNet update components via DLL sideloading (wtsapi32.dll) to inject malicious loaders into svchost.exe and deploy multiple payloads (proxy/loader, execution backdoor, cleaner and a Rust-based backdoor). The report includes IoCs (hashes, IPs), extensive MITRE-mapped TTPs (process injection, service manipulation, tunneling, reconnaissance, indicator removal), detection rules for Kaspersky products and SIEM hunting queries, and mitigation recommendations; attribution to a Chinese-speaking group is given with low confidence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
