# HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy HelloInjector/HelloProxy/HelloBackdoor Toolset Against Russian Government Agencies

> A threat actor tentatively attributed with low confidence to a Chinese-speaking APT group has abused the ViPNet update mechanism (mftp transport, relative-path handling flaw) since at least May 2026, sideloading a malicious wtsapi32.dll (HelloInjector) via the legitimate itcsrvup64.exe binary and injecting into svchost.exe to deploy a five-component custom toolset (HelloInjector, HelloProxy, HelloExecutor, HelloCleaner, HelloBackdoor) against Russian government, energy, transport, education, logistics, and industrial organizations.

- **Published:** 2026-07-19T00:00:00Z
- **Last reviewed:** 2026-07-19T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1528
- **ID:** TL-2026-1528
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 35 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Kaspersky's Global Research and Analysis Team (GReAT) uncovered HelloNet, a sophisticated targeted campaign active since at least May 2026 and still ongoing as of the July 16-19, 2026 disclosure. The intrusion vector abuses InfoTeCS ViPNet — a widely deployed Russian VPN/secure-networking suite used across government and critical-infrastructure networks — specifically a flaw in the mftp update-transport protocol's handling of relative paths in ViPNet Client 4 and ViPNet Administrator. Attackers compromised or spoofed administrator update nodes to push specially crafted 'update' packages that write a malicious library, wtsapi32.dll (dubbed HelloInjector), into the legitimate ViPNet Update System directory (C:\Program Files (x86)\InfoTeCS\VIPNet Update System). At system startup, the trusted, digitally-authorized itcsrvup64.exe binary sideloads this DLL via classic DLL search-order hijacking, giving the malware execution under a trusted process context and bypassing many application-allowlisting and EDR trust heuristics.

HelloInjector then uses NtWriteVirtualMemory and NtCreateThreadEx to inject shellcode into a svchost.exe process specifically selected by searching for instances whose command line contains the 'netsvcs' service group — a well-known technique (process hollowing/injection into a trusted, always-running system process) chosen for stealth and persistence. The payload is stored in plaintext inside the DLL binary itself. HelloInjector additionally establishes a second persistence vector by creating a Windows service named 'AppMgmt' with ServiceDll/ServiceMain registry parameters pointed at the malicious code under HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\Parameters (a form of DLL search-order hijacking / T1543.003 masquerading as the legitimate Windows 'Application Management' service).

Once injected into svchost.exe, the toolset unfolds in stages. HelloProxy is loaded next; it uses the Microsoft Detours hooking library to intercept NtDeviceIoControlFile, closesocket, and shutdown, monitoring AFD_RECV (0x12017) and AFD_GET_TDI_HANDLES (0x12037) IOCTL codes to transparently hijack and proxy legitimate network I/O on the host. HelloProxy listens on TCP ports 5003 and 5060, uses a simple handshake (sends 0x0502, expects the literal string 'ASDFASFSAFASDF' in response) to authenticate operator connections, and logs intercepted traffic to C:\users\public\tesh4RPC.txt. It both forwards proxied traffic and can inject additional executable payloads into memory, acting as the campaign's in-memory loader/multiplexer for subsequent modules.

HelloExecutor is injected via HelloProxy and provides interactive command execution through cmd.exe, used by the operators for hands-on-keyboard reconnaissance: user/account enumeration, network configuration and share discovery, system information gathering, process listing, and file/directory enumeration on the compromised host and adjoining network.

HelloCleaner is a narrowly scoped anti-forensics module whose sole purpose is to delete ViPNet application log files, removing evidence of the malicious update delivery and sideloading events from the very software that was abused to deliver the intrusion — directly undermining defenders' ability to reconstruct the initial-access chain from ViPNet's own audit trail.

HelloBackdoor, found on at least one infected host, is a distinct, Rust-compiled implant (likely a later-stage or higher-value-target tool) that listens for raw TCP connections on port 443 (blending with HTTPS traffic patterns) and requires an activation string of '47c6235b4d2611184' — a truncated MD5 hash fragment of the string 'hello\n' — before responding to commands. Supported commands include !upload and !down for bidirectional file transfer and !stop to terminate. It executes arbitrary attacker commands via cmd.exe and self-deletes using a companion batch script that also restarts the underlying service to preserve persistence continuity. Its Rust toolchain artifacts reference the Chinese USTC (University of Science and Technology of China) Rust crate/package mirror (mirrors.ustc.edu.cn), one of two weak attribution signals Kaspersky cites.

For lateral movement, operators deployed renamed, publicly available PuTTY/Plink SSH utilities (observed as frontpage.exe and pagent.exe, staged from C:\Users\Public\Music) to establish outbound SSH tunnels and reverse port forwards to the primary C2 host 5.39.253.206, with a secondary operations IP of 176.32.34.135 also observed. Two additional dropper/utility binaries were recovered: puh.exe and store.exe (HelloBackdoor droppers), plus a distinct Windows Defender exclusion-configuration utility used to whitelist the malware's working directories and evade AV scanning.

Attribution is explicitly low-confidence: Kaspersky points to an unused/dormant sina.com HTTP header string reference and the Rust USTC mirror artifact as the only Chinese-speaking-APT indicators, while explicitly cautioning that both could be deliberate false-flag operations designed to misdirect attribution toward China given the exclusively Russian government/critical-infrastructure victimology, which would otherwise suggest a different threat actor profile. InfoTeCS has since patched the underlying mftp relative-path handling flaw: ViPNet Client 4 users should update to 4.5.3 (build 65211) or later (4.5.5 build 24733 pending), and ViPNet Administrator users should update to 4.6.11.5113 or later.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1199 Trusted Relationship
- T1569.002 Service Execution
- T1059.003 Windows Command Shell
- T1106 Native API
- T1543.003 Windows Service
- T1574.001 DLL
- T1543.003 Windows Service
- T1055 Process Injection
- T1574.001 DLL
- T1055 Process Injection
- T1036 Masquerading
- T1685.005 Clear Windows Event Logs
- T1070.004 File Deletion
- T1685 Disable or Modify Tools
- T1112 Modify Registry
- T1140 Deobfuscate/Decode Files or Information
- T1033 System Owner/User Discovery
- T1016 System Network Configuration Discovery
- T1049 System Network Connections Discovery
- T1018 Remote System Discovery
- T1082 System Information Discovery
- T1057 Process Discovery
- T1007 System Service Discovery
- T1083 File and Directory Discovery
- T1005 Data from Local System
- T1074.001 Local Data Staging
- T1105 Ingress Tool Transfer
- T1572 Protocol Tunneling
- T1090 Proxy
- T1071 Application Layer Protocol
- T1571 Non-Standard Port
- T1021.004 SSH
- T1041 Exfiltration Over C2 Channel

## Sources

- [Hackers abuse ViPNet software to target Russian govt agencies](https://www.bleepingcomputer.com/news/security/hackers-abuse-vipnet-software-to-target-russian-govt-agencies/)
- [HelloNet campaign: a threat via the ViPNet update system](https://securelist.com/tr/hellonet-vipnet/120700/)
- [Кампания HelloNet: атаки через систему обновления ViPNet](https://securelist.ru/tr/hellonet-vipnet/116327/)
- [«ИнфоТеКС» устранила уязвимость ViPNet, используемую в кампании HelloNet](https://techora.ru/news/infoteks-ustranila-uyazvimost-vipnet-ispolzuemuyu-v-2026-07-17)
- [Российский госсектор и промышленностью атакуют через обновления ViPNet](https://anti-malware.ru/news/2026-07-16-111332/50716?amp=)
- [Kaspersky GReAT: идёт сложная целевая кибератака против российских компаний через механизм обновлений ViPNet](https://safe.cnews.ru/news/line/2026-07-16_kaspersky_great_idet_slozhnaya_tselevaya)
- [Российские компании атакуют через механизм обновлений ViPNet](https://xakep.ru/2026/07/17/hellonet/)
- [HelloNet атакует российские организации через компонент обновления ViPNet](https://www.gs.by/2026/07/17/kampaniya-hellonet-ispolzuet-sistemu-obnovleniya-vipnet-dlya-zakrepleniya-i-zagruzki-vredonosnyh-mod/)
- [Лаборатория Касперского обнаружила кибератаку HelloNet](https://investfuture.ru/articles/laboratoriya-kasperskogo-obnaruzhila-kiberataku-hello-net-37293174)
- [Кампания HelloNet использует систему обновления ViPNet для закрепления и загрузки вредоносных модулей](https://habr.com/ru/news/1060000/)
- [HelloNet campaign: a threat via the ViPNet update system - Threat Radar](https://radar.offseq.com/threat/hellonet-campaign-a-threat-via-the-vipnet-update-s-a8c68453d3754cbe)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1528
