HelloNet ViPNet update-abuse campaign targeting Russian organizations
Campaign
Summary
Hide ▲
Show ▼
The HelloNet campaign is abusing the ViPNet update path to deliver malware to Russian organizations, including government agencies. Active since at least May, it plants wtsapi32.dll in the update directory so itcsrvup64.exe sideloads it at startup. The loader injects into svchost.exe to gain elevated privileges and persistence, then downloads follow-on modules from C2 servers. Impacted sectors include energy, transport, education, and logistics, while attribution to a Chinese-speaking APT remains low confidence.
Related Happenings
HelloInjector/HelloProxy malware activity in ViPNet update abuse
Malware Activity
H score23
First: 19.07.2026 17:23
Last: 19.07.2026 17:23
Sources 1
How related:
HelloInjector runs its embedded payload, which Kaspersky named HelloProxy, in memory and contacts the command-and-control (C2) server to receive additional modules.
About this happening:
The HelloInjector loader is running HelloProxy in memory and pulling additional modules from a C2 server, enabling expanded control over Windows hosts. The mal...
HelloInjector/HelloProxy malware activity in ViPNet update abuse
Malware ActivityHow related: HelloInjector runs its embedded payload, which Kaspersky named HelloProxy, in memory and contacts the command-and-control (C2) server to receive additional modules.
About this happening: The HelloInjector loader is running HelloProxy in memory and pulling additional modules from a C2 server, enabling expanded control over Windows hosts. The mal...
SPECTRALVIPER DLL sideloading backdoor activity
Malware Activity
H score31
First: 11.06.2026 12:45
Last: 11.06.2026 12:45
Sources 1
About this happening:
The SPECTRALVIPER backdoor was executed on affected Windows hosts through a DLL sideloading chain during October 2025 to March 2026, giving operators a way to run...
SPECTRALVIPER DLL sideloading backdoor activity
Malware ActivityAbout this happening: The SPECTRALVIPER backdoor was executed on affected Windows hosts through a DLL sideloading chain during October 2025 to March 2026, giving operators a way to run...
ClockRemoval.ps1 antivirus-disabling malware activity linked to Dragon Boss Solutions LLC
Malware Activity
H score25
First: 15.04.2026 17:40
Last: 15.04.2026 17:40
Sources 1
About this happening:
A signed software operation linked to Dragon Boss Solutions LLC was observed using ClockRemoval.ps1 to disable antivirus on more than 23,000 endpoints worldwide, raisi...
ClockRemoval.ps1 antivirus-disabling malware activity linked to Dragon Boss Solutions LLC
Malware ActivityAbout this happening: A signed software operation linked to Dragon Boss Solutions LLC was observed using ClockRemoval.ps1 to disable antivirus on more than 23,000 endpoints worldwide, raisi...
Bloody Wolf / Stan Ghouls NetSupport RAT spear-phishing campaign
Campaign
H score31
First: 09.02.2026 12:58
Last: 09.02.2026 12:58
Sources 1
About this happening:
The Bloody Wolf / Stan Ghouls operation is actively running a spear-phishing campaign against Uzbekistan and Russia, and the activity matters because it is delivering...
Bloody Wolf / Stan Ghouls NetSupport RAT spear-phishing campaign
CampaignAbout this happening: The Bloody Wolf / Stan Ghouls operation is actively running a spear-phishing campaign against Uzbekistan and Russia, and the activity matters because it is delivering...
Evasive Panda DNS poisoning MgBot espionage campaign
Campaign
H score33
First: 26.12.2025 16:44
Last: 26.12.2025 16:44
Sources 1
About this happening:
Evasive Panda ran a highly targeted cyber espionage campaign that used DNS poisoning to deliver MgBot to victims in Türkiye, China, and India. The operation wa...
Evasive Panda DNS poisoning MgBot espionage campaign
CampaignAbout this happening: Evasive Panda ran a highly targeted cyber espionage campaign that used DNS poisoning to deliver MgBot to victims in Türkiye, China, and India. The operation wa...
Timeline
-
19.07.2026 17:23 2 articles · 18h ago
HelloNet abuses ViPNet updates to target Russian organizations
Initial DisclosureAn advanced threat actor is abusing the ViPNet update mechanism in the HelloNet campaign to target Russian organizations, including government agencies. Kaspersky says the campaign has been active since at least May and uses wtsapi32.dll, dubbed HelloInjector, dropped into the local ViPNet Update System directory so legitimate itcsrvup64.exe loads it at startup; the loader injects into svchost.exe to grant elevated privileges and persistence, then stages additional malware. Kaspersky also says HelloNet has impacted organizations in the government, energy, transport, education, and logistics sectors, and it tentatively attributes the activity to an unidentified Chinese-speaking APT with low confidence while not ruling out a false flag operation.
Show sources
- Hackers abuse ViPNet software to target Russian govt agencies — www.bleepingcomputer.com — 19.07.2026 17:23
- Hackers abuse ViPNet software to target Russian govt agencies — www.bleepingcomputer.com — 19.07.2026 17:23