Threat reportAPTTL-2026-1528
HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy HelloInjector/HelloProxy/HelloBackdoor Toolset Against Russian Government Agencies
HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy (TL-2026-1528), also tracked as HelloNet, is a high-severity advanced persistent threat campaign, first published 2026-07-19. It is linked to a China-nexus actor with low confidence, affects InfoTeCS ViPNet Client 4, maps to 31 MITRE ATT&CK techniques (T1005, T1007, T1016), and is covered by 9 detection rules and 35 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 31MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 35Indicators of compromise
Key facts for TL-2026-1528
- Threat ID
- TL-2026-1528
- Also known as
- HelloNet
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution confidence
- LOW
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government administration, energy, transport, education, logistics, industrial
- Target regions
- russia
- Detection rules
- 9
- Indicators of compromise
- 35
Malware and tooling in HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy
Malware and tooling: HelloBackdoor, HelloCleaner, HelloExecutor, HelloInjector, HelloProxy
How HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy works
A threat actor tentatively attributed with low confidence to a Chinese-speaking APT group has abused the ViPNet update mechanism (mftp transport, relative-path handling flaw) since at least May 2026, sideloading a malicious wtsapi32.dll (HelloInjector) via the legitimate itcsrvup64.exe binary and injecting into svchost.exe to deploy a five-component custom toolset (HelloInjector, HelloProxy, HelloExecutor, HelloCleaner, HelloBackdoor) against Russian government, energy, transport, education, logistics, and industrial organizations.
Kaspersky's Global Research and Analysis Team (GReAT) uncovered HelloNet, a sophisticated targeted campaign active since at least May 2026 and still ongoing as of the July 16-19, 2026 disclosure. The intrusion vector abuses InfoTeCS ViPNet — a widely deployed Russian VPN/secure-networking suite used across government and critical-infrastructure networks — specifically a flaw in the mftp update-transport protocol's handling of relative paths in ViPNet Client 4 and ViPNet Administrator. Attackers compromised or spoofed administrator update nodes to push specially crafted 'update' packages that write a malicious library, wtsapi32.dll (dubbed HelloInjector), into the legitimate ViPNet Update System directory (C:\Program Files (x86)\InfoTeCS\VIPNet Update System). At system startup, the trusted, digitally-authorized itcsrvup64.exe binary sideloads this DLL via classic DLL search-order hijacking, giving the malware execution under a trusted process context and bypassing many application-allowlisting and EDR trust heuristics.
HelloInjector then uses NtWriteVirtualMemory and NtCreateThreadEx to inject shellcode into a svchost.exe process specifically selected by searching for instances whose command line contains the 'netsvcs' service group — a well-known technique (process hollowing/injection into a trusted, always-running system process) chosen for stealth and persistence. The payload is stored in plaintext inside the DLL binary itself. HelloInjector additionally establishes a second persistence vector by creating a Windows service named 'AppMgmt' with ServiceDll/ServiceMain registry parameters pointed at the malicious code under HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\Parameters (a form of DLL search-order hijacking / T1543.003 masquerading as the legitimate Windows 'Application Management' service).
Once injected into svchost.exe, the toolset unfolds in stages. HelloProxy is loaded next; it uses the Microsoft Detours hooking library to intercept NtDeviceIoControlFile, closesocket, and shutdown, monitoring AFD_RECV (0x12017) and AFD_GET_TDI_HANDLES (0x12037) IOCTL codes to transparently hijack and proxy legitimate network I/O on the host. HelloProxy listens on TCP ports 5003 and 5060, uses a simple handshake (sends 0x0502, expects the literal string 'ASDFASFSAFASDF' in response) to authenticate operator connections, and logs intercepted traffic to C:\users\public\tesh4RPC.txt. It both forwards proxied traffic and can inject additional executable payloads into memory, acting as the campaign's in-memory loader/multiplexer for subsequent modules.
HelloExecutor is injected via HelloProxy and provides interactive command execution through cmd.exe, used by the operators for hands-on-keyboard reconnaissance: user/account enumeration, network configuration and share discovery, system information gathering, process listing, and file/directory enumeration on the compromised host and adjoining network.
HelloCleaner is a narrowly scoped anti-forensics module whose sole purpose is to delete ViPNet application log files, removing evidence of the malicious update delivery and sideloading events from the very software that was abused to deliver the intrusion — directly undermining defenders' ability to reconstruct the initial-access chain from ViPNet's own audit trail.
HelloBackdoor, found on at least one infected host, is a distinct, Rust-compiled implant (likely a later-stage or higher-value-target tool) that listens for raw TCP connections on port 443 (blending with HTTPS traffic patterns) and requires an activation string of '47c6235b4d2611184' — a truncated MD5 hash fragment of the string 'hello\n' — before responding to commands. Supported commands include !upload and !down for bidirectional file transfer and !stop to terminate. It executes arbitrary attacker commands via cmd.exe and self-deletes using a companion batch script that also restarts the underlying service to preserve persistence continuity. Its Rust toolchain artifacts reference the Chinese USTC (University of Science and Technology of China) Rust crate/package mirror (mirrors.ustc.edu.cn), one of two weak attribution signals Kaspersky cites.
For lateral movement, operators deployed renamed, publicly available PuTTY/Plink SSH utilities (observed as frontpage.exe and pagent.exe, staged from C:\Users\Public\Music) to establish outbound SSH tunnels and reverse port forwards to the primary C2 host 5.39.253.206, with a secondary operations IP of 176.32.34.135 also observed. Two additional dropper/utility binaries were recovered: puh.exe and store.exe (HelloBackdoor droppers), plus a distinct Windows Defender exclusion-configuration utility used to whitelist the malware's working directories and evade AV scanning.
Attribution is explicitly low-confidence: Kaspersky points to an unused/dormant sina.com HTTP header string reference and the Rust USTC mirror artifact as the only Chinese-speaking-APT indicators, while explicitly cautioning that both could be deliberate false-flag operations designed to misdirect attribution toward China given the exclusively Russian government/critical-infrastructure victimology, which would otherwise suggest a different threat actor profile. InfoTeCS has since patched the underlying mftp relative-path handling flaw: ViPNet Client 4 users should update to 4.5.3 (build 65211) or later (4.5.5 build 24733 pending), and ViPNet Administrator users should update to 4.6.11.5113 or later.
MITRE ATT&CK techniques used in TL-2026-1528
Collection
T1005 Data from Local System; T1074.001 Local Data Staging
Discovery
T1007 System Service Discovery; T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1033 System Owner/User Discovery; T1049 System Network Connections Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery
Lateral Movement
Defense Evasion
T1036 Masquerading; T1055 Process Injection; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information; T1574.001 DLL
Exfiltration
T1041 Exfiltration Over C2 Channel
Privilege Escalation
T1055 Process Injection; T1543.003 Windows Service
Execution
T1059.003 Windows Command Shell; T1106 Native API; T1569.002 Service Execution
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1572 Protocol Tunneling
defense-impairment
T1112 Modify Registry; T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs
Initial Access
T1195 Supply Chain Compromise; T1199 Trusted Relationship
Persistence
stealth
Affected products and versions in HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy
- InfoTeCS — ViPNet Client 4
Vulnerable versions: < 4.5.3 build 65211
Fixed in: 4.5.3 build 65211; 4.5.5 build 24733 (pending) - InfoTeCS — ViPNet Administrator
Vulnerable versions: < 4.6.11.5113
Fixed in: 4.6.11.5113 - InfoTeCS — ViPNet Update System (itcsrvup64.exe component)
Vulnerable versions: all versions predating July 2026 patch
Fixed in: patched alongside ViPNet Client 4 4.5.3 / ViPNet Administrator 4.6.11.5113
Remediation for HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy
Patches
- InfoTeCS ViPNet Client 4: update to 4.5.3 build 65211 or higher (4.5.5 build 24733 pending release)
- InfoTeCS ViPNet Administrator: update to 4.6.11.5113 or higher
Immediate actions
- Update ViPNet Client 4 to version 4.5.3 (build 65211) or higher; 4.5.5 (build 24733) when available
- Update ViPNet Administrator to version 4.6.11.5113 or higher
- Hunt for wtsapi32.dll inside C:\Program Files (x86)\InfoTeCS\VIPNet Update System and validate its digital signature/hash against known-good ViPNet releases
- Inspect svchost.exe instances with 'netsvcs' in their command line for anomalous loaded modules or injected threads
- Search for a Windows service named 'AppMgmt' with unexpected ServiceDll/ServiceMain values under HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\Parameters
- Block/alert on outbound connections to 5.39.253.206 and 176.32.34.135
- Alert on TCP listeners/traffic on ports 5003 and 5060 on ViPNet hosts, and unexpected local processes listening on 443
- Hunt for renamed PuTTY/Plink binaries executing from C:\Users\Public (e.g. frontpage.exe, pagent.exe) establishing SSH tunnels
- Verify integrity of ViPNet update logs; treat unexplained gaps or deletions as evidence of HelloCleaner activity
- Restrict/monitor administrator-node update package delivery over the mftp transport for unexpected relative-path entries
Workarounds
- Restrict write access to C:\Program Files (x86)\InfoTeCS\VIPNet Update System to SYSTEM/TrustedInstaller only
- Disable or tightly control the mftp update transport pending patch deployment
- Enforce out-of-band validation (checksum/signature pinning) of ViPNet update packages before administrator-node distribution
Longer-term hardening
- Deploy EDR with kernel-level API hooking/injection detection tuned for NtWriteVirtualMemory/NtCreateThreadEx cross-process injection into svchost.exe
- Implement application allowlisting that validates DLL provenance/signing for security-software update directories, not just the launching EXE
- Segment and monitor update-distribution infrastructure (ViPNet Administrator nodes) as high-value targets with elevated logging and MFA
- Deploy network-level detection for Detours-style API hooking behavior and AFD IOCTL interception patterns where feasible
- Establish centralized, tamper-resistant logging (forward ViPNet and Windows Security logs off-host) to defeat log-cleaner anti-forensics tooling
Weaknesses (CWE) in HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy
Timeline of HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy
- Kaspersky researchers previously discovered a separate, complex backdoor mimicking ViPNet update traffic during 2025 investigations, establishing prior-year precedent for ViPNet-themed intrusion tooling later linked contextually to the HelloNet cluster.
- HelloNet campaign activity begins, per Kaspersky GReAT telemetry, abusing the ViPNet update mechanism to deliver the HelloInjector DLL against Russian organizations.
- Multi-stage toolset (HelloInjector, HelloProxy, HelloExecutor, HelloCleaner) observed deployed across targeted government, energy, transport, education, and logistics networks.
- Rust-based HelloBackdoor implant identified on at least one infected host, indicating a distinct higher-stage or higher-value-target tool in the campaign's arsenal.
- Kaspersky GReAT updates the Securelist HelloNet report the same day with supplemental detection rules for SIEM, MDR, EDR, and NDR platforms to support defender hunting against the campaign.
- Kaspersky GReAT publishes the HelloNet campaign analysis on Securelist, detailing the ViPNet update-abuse vector, malware toolset, IOCs, and low-confidence Chinese-speaking-APT attribution.
- Russian-language security outlets (Xakep, Anti-Malware.ru, CNews, Habr, GS.by, Techora) republish and amplify the Kaspersky findings.
- InfoTeCS confirms and patches the underlying mftp relative-path handling vulnerability in ViPNet Client 4 (4.5.3 build 65211+) and ViPNet Administrator (4.6.11.5113+).
- BleepingComputer publishes English-language coverage of the campaign, bringing it to a broader international security audience.
Sources cited for HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy
- Hackers abuse ViPNet software to target Russian govt agencies
- HelloNet campaign: a threat via the ViPNet update system
- Кампания HelloNet: атаки через систему обновления ViPNet
- «ИнфоТеКС» устранила уязвимость ViPNet, используемую в кампании HelloNet
- Российский госсектор и промышленностью атакуют через обновления ViPNet
- Kaspersky GReAT: идёт сложная целевая кибератака против российских компаний через механизм обновлений ViPNet
- Российские компании атакуют через механизм обновлений ViPNet
- HelloNet атакует российские организации через компонент обновления ViPNet
- Лаборатория Касперского обнаружила кибератаку HelloNet
- Кампания HelloNet использует систему обновления ViPNet для закрепления и загрузки вредоносных модулей
- HelloNet campaign: a threat via the ViPNet update system - Threat Radar
Detection coverage for TL-2026-1528
As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1528 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.