Hackers abuse ViPNet software to target Russian govt agencies
ID: 6989026f-130b-551b-9390-90b016abe39e
STIX ID: report--6989026f-130b-551b-9390-90b016abe39e
Feed Name: Bleeping Computer
Kaspersky researchers report the HelloNet campaign, active since at least May, in which attackers place a malicious DLL (wtsapi32.dll, HelloInjector) into the ViPNet Update System directory to be sideloaded by a legitimate updater. The loader injects into svchost.exe, runs an in-memory proxy/loader (HelloProxy) and additional modules (HelloExecutor, HelloCleaner, HelloBackdoor) to provide remote command execution, file transfer, cleanup of ViPNet logs, and C2 communications; victims include Russian government, energy, transport, education, and logistics organizations, while attribution remains low-confidence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
