Kaspersky researchers uncovered an active APT campaign dubbed HelloNet, targeting large Russian organizations in government, energy, transport, education, and logistics sectors. Attackers exploit the ViPNet secure network software's update system via DLL sideloading (malicious wtsapi32.dll) to achieve persistence. The toolset includes HelloInjector (a loader injecting into svchost.exe), HelloProxy (a traffic proxy and payload loader using IOCTL interception via Microsoft Detours), HelloExecutor (a reconnaissance backdoor), HelloCleaner (a log-wiping module), and HelloBackdoor (a Rust-based backdoor on port 443 supporting file upload/download and command execution). Attackers used renamed PuTTY/Plink binaries for SSH tunneling. Attribution points tentatively to a Chinese-speaking APT group based on references to sina.com and Rust crate mirrors from USTC, though false flags cannot be ruled out. Detailed IoCs, MITRE ATT&CK TTPs, and detection rules for Kaspersky KEDR Expert and KATA NDR are provided.