bleeping-computer · Crawled Jul 19, 2026
Hackers abuse ViPNet software to target Russian govt agencies
2 IoCs
Read original article ↗
AI Summary
An advanced threat actor is exploiting the update mechanism of the ViPNet software, widely used in Russian government and regulated sectors, to deploy a multi-stage malware payload. The campaign, dubbed HelloNet, has been active since at least May 2026 and targets organizations in government, energy, transport, education, and logistics. The attackers use a malicious DLL sideloaded via a legitimate ViPNet updater to establish persistence and deploy proxy and backdoor tools. Attribution to a Chinese-speaking APT is considered low confidence due to limited evidence and potential false flags.
AI-extracted · verify before operational use