HelloInjector/HelloProxy malware activity in ViPNet update abuse
Malware Activity
Summary
Hide ▲
Show ▼
The HelloInjector loader is running HelloProxy in memory and pulling additional modules from a C2 server, enabling expanded control over Windows hosts. The malware is delivered as wtsapi32.dll through the ViPNet Update System and sideloaded by itcsrvup64.exe at startup. It injects into svchost.exe to gain elevated privileges and persistence across reboots. The activity is part of HelloNet, which is targeting Russian organizations across multiple sectors.
Related Happenings
HelloNet ViPNet update-abuse campaign targeting Russian organizations
Campaign
H score33
First: 19.07.2026 17:23
Last: 19.07.2026 17:23
Sources 1
How related:
Dubbed HelloNet, the campaign has been active since at least May, deploying a malicious payload that acts as a proxy and loader for additional malware.
About this happening:
The HelloNet campaign is abusing the ViPNet update path to deliver malware to Russian organizations, including government agencies. Active since at least May,...
HelloNet ViPNet update-abuse campaign targeting Russian organizations
CampaignHow related: Dubbed HelloNet, the campaign has been active since at least May, deploying a malicious payload that acts as a proxy and loader for additional malware.
About this happening: The HelloNet campaign is abusing the ViPNet update path to deliver malware to Russian organizations, including government agencies. Active since at least May,...
SPECTRALVIPER DLL sideloading backdoor activity
Malware Activity
H score31
First: 11.06.2026 12:45
Last: 11.06.2026 12:45
Sources 1
About this happening:
The SPECTRALVIPER backdoor was executed on affected Windows hosts through a DLL sideloading chain during October 2025 to March 2026, giving operators a way to run...
SPECTRALVIPER DLL sideloading backdoor activity
Malware ActivityAbout this happening: The SPECTRALVIPER backdoor was executed on affected Windows hosts through a DLL sideloading chain during October 2025 to March 2026, giving operators a way to run...
STX RAT trojanized CPU-Z and HWMonitor distribution
Malware Activity
H score21
First: 12.04.2026 08:54
Last: 12.04.2026 08:54
Sources 1
About this happening:
A trojanized CPU-Z and HWMonitor distribution pushed STX RAT through DLL side-loading, exposing downloaders to remote access and infostealing risk. The payload...
STX RAT trojanized CPU-Z and HWMonitor distribution
Malware ActivityAbout this happening: A trojanized CPU-Z and HWMonitor distribution pushed STX RAT through DLL side-loading, exposing downloaders to remote access and infostealing risk. The payload...
Timeline
-
19.07.2026 17:23 2 articles · 18h ago
HelloNet abuses ViPNet updates against Russian organizations
Initial DisclosureKaspersky reports that an advanced threat actor is abusing the ViPNet update mechanism in the HelloNet campaign to target Russian organizations, including government agencies. The activity has been active since at least May and drops wtsapi32.dll (HelloInjector) into the ViPNet Update System directory so it can be sideloaded by itcsrvup64.exe at startup. HelloInjector runs HelloProxy in memory, reaches a C2 server, and pulls additional modules including HelloExecutor, HelloCleaner, and HelloBackdoor. Kaspersky tentatively attributes the campaign to an unidentified Chinese-speaking APT, but says the evidence is weak.
Show sources
- Hackers abuse ViPNet software to target Russian govt agencies — www.bleepingcomputer.com — 19.07.2026 17:23
- Hackers abuse ViPNet software to target Russian govt agencies — www.bleepingcomputer.com — 19.07.2026 17:23