Securelist
Read post

HelloNet campaign: a threat via the ViPNet update system

Kaspersky researchers uncovered an active APT campaign dubbed HelloNet, targeting large Russian organizations in government, energy, transport, education, and logistics sectors. Attackers exploit the ViPNet secure network software's update system via DLL sideloading (malicious wtsapi32.dll) to achieve persistence. The toolset includes HelloInjector (a loader injecting into svchost.exe), HelloProxy (a traffic proxy and payload loader using IOCTL interception via Microsoft Detours), HelloExecutor (a reconnaissance backdoor), HelloCleaner (a log-wiping module), and HelloBackdoor (a Rust-based backdoor on port 443 supporting file upload/download and command execution). Attackers used renamed PuTTY/Plink binaries for SSH tunneling. Attribution points tentatively to a Chinese-speaking APT group based on references to sina.com and Rust crate mirrors from USTC, though false flags cannot be ruled out. Detailed IoCs, MITRE ATT&CK TTPs, and detection rules for Kaspersky KEDR Expert and KATA NDR are provided.

    #cyber#rust#malware
Jul 16•10m read time•From securelist.com
Post cover image
Table of contents
Persistence via the update systemHelloInjector — a loader for additional malicious componentsHelloProxy — a tool for traffic proxying and launching new malicious payloadsHelloBackdoor — a Rust-based backdoor for file system manipulationsAttributionRecommendationsDetection by Kaspersky solutionsIndicators of Compromise
257 Impressions
Securelist's image
Securelist

Securelist is a cybersecurity blog and research platform operated by Kaspersky Lab. It offers insigh...

74 Followers

•

164 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard