An advanced threat actor is exploiting the update mechanism of InfoTeCS’s ViPNet security software to deploy malicious payloads and conduct espionage against various Russian government and industrial organizations.
Key Points
- The HelloNet campaign has targeted Russian government, energy, transport, and education sectors since at least May 2024.
- Attackers sideload a malicious DLL, HelloInjector, through the legitimate ViPNet update process to gain elevated Windows privileges.
- The malware suite includes HelloProxy for C2 communication, HelloExecutor for reconnaissance, and HelloCleaner to delete forensic logs.
- Kaspersky researchers tentatively attribute the campaign to a Chinese-speaking threat group, though they note the evidence may be a false flag.
- Security teams are advised to monitor network traffic on ports 5003, 5060, and 443 to detect potential HelloNet activity.