HelloBackdoor is a Rust-based backdoor associated with the HelloNet intrusion set targeting Russian organizations. It has been observed in campaigns abusing the ViPNet update mechanism, where attackers used DLL sideloading through a malicious component loaded by a legitimate ViPNet updater process to establish persistence and launch additional malware modules. Within this toolchain, HelloBackdoor appears as a later-stage implant deployed alongside components such as HelloInjector, HelloProxy, HelloExecutor, and HelloCleaner.
The malware provides remote command execution and bidirectional file transfer, allowing operators to upload and download files and execute arbitrary commands through the Windows command interpreter. Reporting also indicates it can terminate itself on command. Its role in the broader operation is consistent with post-compromise access, hands-on-keyboard activity, and data movement after an initial foothold has been established.
HelloBackdoor has been documented on compromised Windows systems in Russian government, energy, transport, education, logistics, and industrial environments. The broader campaign has been characterized as cyber-espionage. Attribution to a Chinese-speaking threat actor has been assessed only with low confidence, and false-flag possibilities have been noted, so actor attribution remains unconfirmed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The deployed malware, HelloProxy, contacts a command-and-control server for additional modules like HelloExecutor (a backdoor) and HelloBackdoor (a Rust-based implant).
6 distinct techniques documented for this family, organized by ATT&CK tactic.
SysExcSvc.dll, for receiving commands and exfiltrating their results back to Microsoft OneDrive cloud storage that's used as command-and-control (C2)
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rust-based implant that supports file upload and download operations with the C2 server and executes unmatched commands via cmd.exe.
A Rust-based backdoor component in the HelloNet toolkit used for file transfer.
A Rust-based implant delivered as an additional module in the HelloNet campaign.
Rust-based implant that supports file upload/download and command execution, communicating over port 443.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.