A threat actor known as HelloNet is abusing the ViPNet update mechanism to target Russian organizations, including government agencies, by deploying malware that acts as a proxy, loader, and backdoor. Kaspersky says the campaign has affected multiple sectors and may involve a Chinese-speaking APT group, though the attribution remains low confidence. #HelloNet #ViPNet #HelloInjector #HelloProxy #HelloExecutor #HelloCleaner #HelloBackdoor #InfoTeCS
Keypoints
- HelloNet has been active since at least May.
- The campaign targets Russian organizations, including government agencies.
- Attackers abuse the ViPNet update mechanism to sideload a malicious DLL.
- HelloInjector loads HelloProxy, which fetches additional modules from a C2 server.
- Kaspersky links the activity to a possible Chinese-speaking APT group with low confidence.