<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/hackers-abuse-vipnet-software-to-target-russian-govt-agencies-mwtmhyxon" -->

---
title: Hackers abuse ViPNet software to target Russian govt...
description: An advanced threat actor dubbed HelloNet is abusing the update mechanism of ViPNet, a widely-used Russian VPN and network security suite, to target Russian...
canonical: https://daily.dev/posts/hackers-abuse-vipnet-software-to-target-russian-govt-agencies-mwtmhyxon
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Hackers abuse ViPNet software to target Russian govt agencies | daily.dev
og:description: An advanced threat actor dubbed HelloNet is abusing the update mechanism of ViPNet, a widely-used Russian VPN and network security suite, to target Russian...
og:url: https://daily.dev/posts/hackers-abuse-vipnet-software-to-target-russian-govt-agencies-mwtmhyxon
og:image: https://api.daily.dev/og/posts/mWtmHYXOn.png
og:image:alt: Hackers abuse ViPNet software to target Russian govt agencies
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Hackers abuse ViPNet software to target Russian govt agencies

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

An advanced threat actor dubbed HelloNet is abusing the update mechanism of ViPNet, a widely-used Russian VPN and network security suite, to target Russian government agencies, energy, transport, education, and logistics organizations. Attackers place a malicious DLL (HelloInjector) in the ViPNet Update System directory, which is sideloaded at startup via a legitimate executable, injecting into svchost.exe for persistence and elevated privileges. The malware toolset includes HelloProxy (C2 proxy), HelloExecutor (backdoor for command execution and network reconnaissance), HelloCleaner (log removal), and HelloBackdoor (Rust-based file upload/download and command execution). Kaspersky tentatively attributes the campaign to a Chinese-speaking APT group but assigns low confidence due to weak evidence and possible false flag indicators. Recommended mitigations include monitoring traffic on ports 5003, 5060, and 443 on systems running ViPNet.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/hackers-abuse-vipnet-software-to-target-russian-govt-agencies>

---

Tags: [#malware](https://daily.dev/tags/malware), [#kaspersky](https://daily.dev/tags/kaspersky)

[View this post on daily.dev](https://daily.dev/posts/hackers-abuse-vipnet-software-to-target-russian-govt-agencies-mwtmhyxon)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Hackers abuse ViPNet software to target Russian govt agencies","url":"https://daily.dev/posts/hackers-abuse-vipnet-software-to-target-russian-govt-agencies-mwtmhyxon","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/hackers-abuse-vipnet-software-to-target-russian-govt-agencies-mwtmhyxon"},"datePublished":"2026-07-19T14:35:08.085Z","dateModified":"2026-07-19T14:36:09.347Z","description":"An advanced threat actor dubbed HelloNet is abusing the update mechanism of ViPNet, a widely-used Russian VPN and network security suite, to target Russian...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4459db2c7d6e0896d65a54be95410cac?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4459db2c7d6e0896d65a54be95410cac?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/hackers-abuse-vipnet-software-to-target-russian-govt-agencies-mwtmhyxon","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"malware,kaspersky","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Hackers abuse ViPNet software to target Russian govt agencies"}]}
```

