Threat Intelligence HelloNet campaign abuses ViPNet update mechanism to target Russian organizations July 20, 2026 Share By SC Staff An advanced threat actor, dubbed HelloNet, is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. The campaign has been active since at least May, deploying a malicious payload that acts as a proxy and loader for additional malware. According to Kaspersky researchers, HelloNet has impacted organizations in the government, energy, transport, education, and logistics sectors, with further coverage provided by Bleeping Computer. The HelloNet campaign targets organizations using ViPNet, a Russian information-security product suite commonly used in government and regulated environments. Attackers place a malicious DLL file, HelloInjector, within the ViPNet Update System directory. This file is then sideloaded at startup, injecting into the svchost.exe process to gain elevated privileges and persistence. While the initial access method is not detailed, it's noted that ViPNet's update infrastructure itself may not have been compromised. The deployed malware, HelloProxy, contacts a command-and-control server for additional modules like HelloExecutor (a backdoor) and HelloBackdoor (a Rust-based implant). A tool called HelloCleaner is also used to erase ViPNet log data. Kaspersky tentatively attributes the campaign to an unidentified Chinese-speaking APT group but notes low confidence due to weak evidence. Security teams are advised to monitor ViPNet systems for suspicious traffic on specific ports. Source: Bleeping Computer SC Staff Related Threat Intelligence 2 charged in New York for laundering $43 million from investment scams SC Staff July 17, 2026 Zhuoying Chen, 27, and Haojie Zhang, 38, are accused of managing a network that transferred at least $43 million to China, based on information published by Bleeping Computer. Threat Intelligence New Russian-speaking threat actor UAT-11795 targets US and Europe with novel malware SC Staff July 17, 2026 UAT-11795 utilizes novel tools, including the Python-based Starland RAT and the PowerShell-based WLDR agent, which operates entirely in-memory with encrypted beaconing and a Runspace execution engine. EDR How to Evaluate Threat Intelligence and Threat Management Platforms SC Media Editorial Intelligence, reviewed by Dustin Sachs July 17, 2026 Platform success depends on turning findings into operational improvements Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Account Harvesting DNS Spoofing Deauthentication Attack Defacement Dictionary Attack Distributed Scans Dumpster Diving Fault Line Attacks Google Hacking Hybrid Attack You can skip this ad in 5 seconds