Threat reportAPTTL-2026-1528

HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy HelloInjector/HelloProxy/HelloBackdoor Toolset Against Russian Government Agencies

highACTIVE

HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy (TL-2026-1528), also tracked as HelloNet, is a high-severity advanced persistent threat campaign, first published 2026-07-19. It is linked to a China-nexus actor with low confidence, affects InfoTeCS ViPNet Client 4, maps to 31 MITRE ATT&CK techniques (T1005, T1007, T1016), and is covered by 9 detection rules and 35 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
31MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
35Indicators of compromise

Key facts for TL-2026-1528

Threat ID
TL-2026-1528
Also known as
HelloNet
Severity
HIGH
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution confidence
LOW
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government administration, energy, transport, education, logistics, industrial
Target regions
russia
Detection rules
9
Indicators of compromise
35

Malware and tooling in HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy

Malware and tooling: HelloBackdoor, HelloCleaner, HelloExecutor, HelloInjector, HelloProxy

How HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy works

A threat actor tentatively attributed with low confidence to a Chinese-speaking APT group has abused the ViPNet update mechanism (mftp transport, relative-path handling flaw) since at least May 2026, sideloading a malicious wtsapi32.dll (HelloInjector) via the legitimate itcsrvup64.exe binary and injecting into svchost.exe to deploy a five-component custom toolset (HelloInjector, HelloProxy, HelloExecutor, HelloCleaner, HelloBackdoor) against Russian government, energy, transport, education, logistics, and industrial organizations.

Kaspersky's Global Research and Analysis Team (GReAT) uncovered HelloNet, a sophisticated targeted campaign active since at least May 2026 and still ongoing as of the July 16-19, 2026 disclosure. The intrusion vector abuses InfoTeCS ViPNet — a widely deployed Russian VPN/secure-networking suite used across government and critical-infrastructure networks — specifically a flaw in the mftp update-transport protocol's handling of relative paths in ViPNet Client 4 and ViPNet Administrator. Attackers compromised or spoofed administrator update nodes to push specially crafted 'update' packages that write a malicious library, wtsapi32.dll (dubbed HelloInjector), into the legitimate ViPNet Update System directory (C:\Program Files (x86)\InfoTeCS\VIPNet Update System). At system startup, the trusted, digitally-authorized itcsrvup64.exe binary sideloads this DLL via classic DLL search-order hijacking, giving the malware execution under a trusted process context and bypassing many application-allowlisting and EDR trust heuristics.

HelloInjector then uses NtWriteVirtualMemory and NtCreateThreadEx to inject shellcode into a svchost.exe process specifically selected by searching for instances whose command line contains the 'netsvcs' service group — a well-known technique (process hollowing/injection into a trusted, always-running system process) chosen for stealth and persistence. The payload is stored in plaintext inside the DLL binary itself. HelloInjector additionally establishes a second persistence vector by creating a Windows service named 'AppMgmt' with ServiceDll/ServiceMain registry parameters pointed at the malicious code under HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\Parameters (a form of DLL search-order hijacking / T1543.003 masquerading as the legitimate Windows 'Application Management' service).

Once injected into svchost.exe, the toolset unfolds in stages. HelloProxy is loaded next; it uses the Microsoft Detours hooking library to intercept NtDeviceIoControlFile, closesocket, and shutdown, monitoring AFD_RECV (0x12017) and AFD_GET_TDI_HANDLES (0x12037) IOCTL codes to transparently hijack and proxy legitimate network I/O on the host. HelloProxy listens on TCP ports 5003 and 5060, uses a simple handshake (sends 0x0502, expects the literal string 'ASDFASFSAFASDF' in response) to authenticate operator connections, and logs intercepted traffic to C:\users\public\tesh4RPC.txt. It both forwards proxied traffic and can inject additional executable payloads into memory, acting as the campaign's in-memory loader/multiplexer for subsequent modules.

HelloExecutor is injected via HelloProxy and provides interactive command execution through cmd.exe, used by the operators for hands-on-keyboard reconnaissance: user/account enumeration, network configuration and share discovery, system information gathering, process listing, and file/directory enumeration on the compromised host and adjoining network.

HelloCleaner is a narrowly scoped anti-forensics module whose sole purpose is to delete ViPNet application log files, removing evidence of the malicious update delivery and sideloading events from the very software that was abused to deliver the intrusion — directly undermining defenders' ability to reconstruct the initial-access chain from ViPNet's own audit trail.

HelloBackdoor, found on at least one infected host, is a distinct, Rust-compiled implant (likely a later-stage or higher-value-target tool) that listens for raw TCP connections on port 443 (blending with HTTPS traffic patterns) and requires an activation string of '47c6235b4d2611184' — a truncated MD5 hash fragment of the string 'hello\n' — before responding to commands. Supported commands include !upload and !down for bidirectional file transfer and !stop to terminate. It executes arbitrary attacker commands via cmd.exe and self-deletes using a companion batch script that also restarts the underlying service to preserve persistence continuity. Its Rust toolchain artifacts reference the Chinese USTC (University of Science and Technology of China) Rust crate/package mirror (mirrors.ustc.edu.cn), one of two weak attribution signals Kaspersky cites.

For lateral movement, operators deployed renamed, publicly available PuTTY/Plink SSH utilities (observed as frontpage.exe and pagent.exe, staged from C:\Users\Public\Music) to establish outbound SSH tunnels and reverse port forwards to the primary C2 host 5.39.253.206, with a secondary operations IP of 176.32.34.135 also observed. Two additional dropper/utility binaries were recovered: puh.exe and store.exe (HelloBackdoor droppers), plus a distinct Windows Defender exclusion-configuration utility used to whitelist the malware's working directories and evade AV scanning.

Attribution is explicitly low-confidence: Kaspersky points to an unused/dormant sina.com HTTP header string reference and the Rust USTC mirror artifact as the only Chinese-speaking-APT indicators, while explicitly cautioning that both could be deliberate false-flag operations designed to misdirect attribution toward China given the exclusively Russian government/critical-infrastructure victimology, which would otherwise suggest a different threat actor profile. InfoTeCS has since patched the underlying mftp relative-path handling flaw: ViPNet Client 4 users should update to 4.5.3 (build 65211) or later (4.5.5 build 24733 pending), and ViPNet Administrator users should update to 4.6.11.5113 or later.

MITRE ATT&CK techniques used in TL-2026-1528

Collection

T1005 Data from Local System; T1074.001 Local Data Staging

Discovery

T1007 System Service Discovery; T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1033 System Owner/User Discovery; T1049 System Network Connections Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery

Lateral Movement

T1021.004 SSH

Defense Evasion

T1036 Masquerading; T1055 Process Injection; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information; T1574.001 DLL

Exfiltration

T1041 Exfiltration Over C2 Channel

Privilege Escalation

T1055 Process Injection; T1543.003 Windows Service

Execution

T1059.003 Windows Command Shell; T1106 Native API; T1569.002 Service Execution

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1572 Protocol Tunneling

defense-impairment

T1112 Modify Registry; T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs

Initial Access

T1195 Supply Chain Compromise; T1199 Trusted Relationship

Persistence

T1543.003 Windows Service

stealth

T1574.001 DLL

Affected products and versions in HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy

  • InfoTeCS — ViPNet Client 4
    Vulnerable versions: < 4.5.3 build 65211
    Fixed in: 4.5.3 build 65211; 4.5.5 build 24733 (pending)
  • InfoTeCS — ViPNet Administrator
    Vulnerable versions: < 4.6.11.5113
    Fixed in: 4.6.11.5113
  • InfoTeCS — ViPNet Update System (itcsrvup64.exe component)
    Vulnerable versions: all versions predating July 2026 patch
    Fixed in: patched alongside ViPNet Client 4 4.5.3 / ViPNet Administrator 4.6.11.5113

Remediation for HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy

Patches

  • InfoTeCS ViPNet Client 4: update to 4.5.3 build 65211 or higher (4.5.5 build 24733 pending release)
  • InfoTeCS ViPNet Administrator: update to 4.6.11.5113 or higher

Immediate actions

  • Update ViPNet Client 4 to version 4.5.3 (build 65211) or higher; 4.5.5 (build 24733) when available
  • Update ViPNet Administrator to version 4.6.11.5113 or higher
  • Hunt for wtsapi32.dll inside C:\Program Files (x86)\InfoTeCS\VIPNet Update System and validate its digital signature/hash against known-good ViPNet releases
  • Inspect svchost.exe instances with 'netsvcs' in their command line for anomalous loaded modules or injected threads
  • Search for a Windows service named 'AppMgmt' with unexpected ServiceDll/ServiceMain values under HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\Parameters
  • Block/alert on outbound connections to 5.39.253.206 and 176.32.34.135
  • Alert on TCP listeners/traffic on ports 5003 and 5060 on ViPNet hosts, and unexpected local processes listening on 443
  • Hunt for renamed PuTTY/Plink binaries executing from C:\Users\Public (e.g. frontpage.exe, pagent.exe) establishing SSH tunnels
  • Verify integrity of ViPNet update logs; treat unexplained gaps or deletions as evidence of HelloCleaner activity
  • Restrict/monitor administrator-node update package delivery over the mftp transport for unexpected relative-path entries

Workarounds

  • Restrict write access to C:\Program Files (x86)\InfoTeCS\VIPNet Update System to SYSTEM/TrustedInstaller only
  • Disable or tightly control the mftp update transport pending patch deployment
  • Enforce out-of-band validation (checksum/signature pinning) of ViPNet update packages before administrator-node distribution

Longer-term hardening

  • Deploy EDR with kernel-level API hooking/injection detection tuned for NtWriteVirtualMemory/NtCreateThreadEx cross-process injection into svchost.exe
  • Implement application allowlisting that validates DLL provenance/signing for security-software update directories, not just the launching EXE
  • Segment and monitor update-distribution infrastructure (ViPNet Administrator nodes) as high-value targets with elevated logging and MFA
  • Deploy network-level detection for Detours-style API hooking behavior and AFD IOCTL interception patterns where feasible
  • Establish centralized, tamper-resistant logging (forward ViPNet and Windows Security logs off-host) to defeat log-cleaner anti-forensics tooling

Weaknesses (CWE) in HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy

CWE-427, CWE-22, CWE-434, CWE-706, CWE-115

Timeline of HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy

  • Kaspersky researchers previously discovered a separate, complex backdoor mimicking ViPNet update traffic during 2025 investigations, establishing prior-year precedent for ViPNet-themed intrusion tooling later linked contextually to the HelloNet cluster.
  • HelloNet campaign activity begins, per Kaspersky GReAT telemetry, abusing the ViPNet update mechanism to deliver the HelloInjector DLL against Russian organizations.
  • Multi-stage toolset (HelloInjector, HelloProxy, HelloExecutor, HelloCleaner) observed deployed across targeted government, energy, transport, education, and logistics networks.
  • Rust-based HelloBackdoor implant identified on at least one infected host, indicating a distinct higher-stage or higher-value-target tool in the campaign's arsenal.
  • Kaspersky GReAT updates the Securelist HelloNet report the same day with supplemental detection rules for SIEM, MDR, EDR, and NDR platforms to support defender hunting against the campaign.
  • Kaspersky GReAT publishes the HelloNet campaign analysis on Securelist, detailing the ViPNet update-abuse vector, malware toolset, IOCs, and low-confidence Chinese-speaking-APT attribution.
  • Russian-language security outlets (Xakep, Anti-Malware.ru, CNews, Habr, GS.by, Techora) republish and amplify the Kaspersky findings.
  • InfoTeCS confirms and patches the underlying mftp relative-path handling vulnerability in ViPNet Client 4 (4.5.3 build 65211+) and ViPNet Administrator (4.6.11.5113+).
  • BleepingComputer publishes English-language coverage of the campaign, bringing it to a broader international security audience.

Sources cited for HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy

Detection coverage for TL-2026-1528

As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1528 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
35 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats