bleeping-computer · Crawled Jul 19, 2026

Hackers abuse ViPNet software to target Russian govt agencies

2 IoCs
Read original article ↗

AI Summary

An advanced threat actor is exploiting the update mechanism of the ViPNet software, widely used in Russian government and regulated sectors, to deploy a multi-stage malware payload. The campaign, dubbed HelloNet, has been active since at least May 2026 and targets organizations in government, energy, transport, education, and logistics. The attackers use a malicious DLL sideloaded via a legitimate ViPNet updater to establish persistence and deploy proxy and backdoor tools. Attribution to a Chinese-speaking APT is considered low confidence due to limited evidence and potential false flags.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
Filename wtsapi32.dll Details →
Filename itcsrvup64.exe Details →