Find notable cyber news and cases, enriched with sources, timelines, and signals.

HelloInjector/HelloProxy malware activity in ViPNet update abuse

Malware Activity
First reported
Last updated
Happening score
H score 23
1 unique sources, 1 articles

Summary

Hide ▲

The HelloInjector loader is running HelloProxy in memory and pulling additional modules from a C2 server, enabling expanded control over Windows hosts. The malware is delivered as wtsapi32.dll through the ViPNet Update System and sideloaded by itcsrvup64.exe at startup. It injects into svchost.exe to gain elevated privileges and persistence across reboots. The activity is part of HelloNet, which is targeting Russian organizations across multiple sectors.

Related Happenings

HelloNet ViPNet update-abuse campaign targeting Russian organizations

Campaign
H score33 First: 19.07.2026 17:23 Last: 19.07.2026 17:23 Sources 1

How related: Dubbed HelloNet, the campaign has been active since at least May, deploying a malicious payload that acts as a proxy and loader for additional malware.

About this happening: The HelloNet campaign is abusing the ViPNet update path to deliver malware to Russian organizations, including government agencies. Active since at least May,...

SPECTRALVIPER DLL sideloading backdoor activity

Malware Activity
H score31 First: 11.06.2026 12:45 Last: 11.06.2026 12:45 Sources 1

About this happening: The SPECTRALVIPER backdoor was executed on affected Windows hosts through a DLL sideloading chain during October 2025 to March 2026, giving operators a way to run...

STX RAT trojanized CPU-Z and HWMonitor distribution

Malware Activity
H score21 First: 12.04.2026 08:54 Last: 12.04.2026 08:54 Sources 1

About this happening: A trojanized CPU-Z and HWMonitor distribution pushed STX RAT through DLL side-loading, exposing downloaders to remote access and infostealing risk. The payload...

Timeline

  1. 19.07.2026 17:23 2 articles · 18h ago

    HelloNet abuses ViPNet updates against Russian organizations

    Initial Disclosure

    Kaspersky reports that an advanced threat actor is abusing the ViPNet update mechanism in the HelloNet campaign to target Russian organizations, including government agencies. The activity has been active since at least May and drops wtsapi32.dll (HelloInjector) into the ViPNet Update System directory so it can be sideloaded by itcsrvup64.exe at startup. HelloInjector runs HelloProxy in memory, reaches a C2 server, and pulls additional modules including HelloExecutor, HelloCleaner, and HelloBackdoor. Kaspersky tentatively attributes the campaign to an unidentified Chinese-speaking APT, but says the evidence is weak.

    Show sources