AUTO-UPDATED

Hackers abuse ViPNet software to target Russian govt agencies

An advanced threat actor is exploiting the update mechanism of InfoTeCS’s ViPNet security software to deploy malicious payloads and conduct espionage against various Russian government and industrial organizations.

Key Points

  • The HelloNet campaign has targeted Russian government, energy, transport, and education sectors since at least May 2024.
  • Attackers sideload a malicious DLL, HelloInjector, through the legitimate ViPNet update process to gain elevated Windows privileges.
  • The malware suite includes HelloProxy for C2 communication, HelloExecutor for reconnaissance, and HelloCleaner to delete forensic logs.
  • Kaspersky researchers tentatively attribute the campaign to a Chinese-speaking threat group, though they note the evidence may be a false flag.
  • Security teams are advised to monitor network traffic on ports 5003, 5060, and 443 to detect potential HelloNet activity.

Why it Matters

This campaign highlights the significant risks posed when attackers compromise widely used, high-trust security infrastructure within regulated environments. By abusing legitimate update mechanisms, threat actors can maintain persistent access to sensitive government and industrial networks while effectively evading standard security detection.
BleepingComputer Published by Bill Toulas
Read original