Find notable cyber news and cases, enriched with sources, timelines, and signals.

HelloNet ViPNet update-abuse campaign targeting Russian organizations

Campaign
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

The HelloNet campaign is abusing the ViPNet update path to deliver malware to Russian organizations, including government agencies. Active since at least May, it plants wtsapi32.dll in the update directory so itcsrvup64.exe sideloads it at startup. The loader injects into svchost.exe to gain elevated privileges and persistence, then downloads follow-on modules from C2 servers. Impacted sectors include energy, transport, education, and logistics, while attribution to a Chinese-speaking APT remains low confidence.

Related Happenings

HelloInjector/HelloProxy malware activity in ViPNet update abuse

Malware Activity
H score23 First: 19.07.2026 17:23 Last: 19.07.2026 17:23 Sources 1

How related: HelloInjector runs its embedded payload, which Kaspersky named HelloProxy, in memory and contacts the command-and-control (C2) server to receive additional modules.

About this happening: The HelloInjector loader is running HelloProxy in memory and pulling additional modules from a C2 server, enabling expanded control over Windows hosts. The mal...

SPECTRALVIPER DLL sideloading backdoor activity

Malware Activity
H score31 First: 11.06.2026 12:45 Last: 11.06.2026 12:45 Sources 1

About this happening: The SPECTRALVIPER backdoor was executed on affected Windows hosts through a DLL sideloading chain during October 2025 to March 2026, giving operators a way to run...

ClockRemoval.ps1 antivirus-disabling malware activity linked to Dragon Boss Solutions LLC

Malware Activity
H score25 First: 15.04.2026 17:40 Last: 15.04.2026 17:40 Sources 1

About this happening: A signed software operation linked to Dragon Boss Solutions LLC was observed using ClockRemoval.ps1 to disable antivirus on more than 23,000 endpoints worldwide, raisi...

Bloody Wolf / Stan Ghouls NetSupport RAT spear-phishing campaign

Campaign
H score31 First: 09.02.2026 12:58 Last: 09.02.2026 12:58 Sources 1

About this happening: The Bloody Wolf / Stan Ghouls operation is actively running a spear-phishing campaign against Uzbekistan and Russia, and the activity matters because it is delivering...

Evasive Panda DNS poisoning MgBot espionage campaign

Campaign
H score33 First: 26.12.2025 16:44 Last: 26.12.2025 16:44 Sources 1

About this happening: Evasive Panda ran a highly targeted cyber espionage campaign that used DNS poisoning to deliver MgBot to victims in Türkiye, China, and India. The operation wa...

Timeline

  1. 19.07.2026 17:23 2 articles · 18h ago

    HelloNet abuses ViPNet updates to target Russian organizations

    Initial Disclosure

    An advanced threat actor is abusing the ViPNet update mechanism in the HelloNet campaign to target Russian organizations, including government agencies. Kaspersky says the campaign has been active since at least May and uses wtsapi32.dll, dubbed HelloInjector, dropped into the local ViPNet Update System directory so legitimate itcsrvup64.exe loads it at startup; the loader injects into svchost.exe to grant elevated privileges and persistence, then stages additional malware. Kaspersky also says HelloNet has impacted organizations in the government, energy, transport, education, and logistics sectors, and it tentatively attributes the activity to an unidentified Chinese-speaking APT with low confidence while not ruling out a false flag operation.

    Show sources