Hackers Abuse ViPNet Software to Target Russian Government Agencies
ID: 82af72f6-ae79-58b1-85c6-e76d6ce39b73
STIX ID: report--82af72f6-ae79-58b1-85c6-e76d6ce39b73
Feed Name: CosmicBytez Labs
HelloNet is an active, supply-chain-adjacent campaign (disclosed 16 July 2026) that leverages DLL sideloading of ViPNet Client's update component to achieve persistence and deploy a modular malware suite (HelloInjector, HelloProxy, HelloExecutor, HelloCleaner, HelloBackdoor) against Russian government, energy, transport, education, logistics, and industrial targets; Kaspersky observed C2 traffic to 5.39.253.206 on ports 443, 5003, and 5060, and InfoTeCS published patches and YARA rules on 17 July 2026. Attribution to a Chinese-speaking APT is assessed with low confidence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
