HelloExecutor is a Windows backdoor used in the HelloNet intrusion set targeting Russian organizations. It has been observed in campaigns abusing the ViPNet update mechanism, where attackers use DLL sideloading through a trusted ViPNet component to establish persistence and load additional malware modules. Within this toolchain, HelloExecutor is delivered as a follow-on module by HelloProxy and operates from an already compromised host.
Its primary functions are remote command execution and host and network reconnaissance. Operators used it to run shell commands, enumerate users and groups, inspect network configuration, and collect information about installed ViPNet software and the surrounding environment. Reporting also indicates it was used alongside SSH tunneling to support attacker access to compromised infrastructure. The malware has been associated with espionage activity affecting Russian government, energy, transport, education, logistics, industrial, electronics, instrumentation, IT, and software-development organizations.
HelloExecutor has been described as part of a broader malware cluster that also includes HelloInjector, HelloProxy, HelloCleaner, and the Rust-based HelloBackdoor. Attribution of the overall campaign to a Chinese-speaking threat actor has been assessed only with low confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The deployed malware, HelloProxy, contacts a command-and-control server for additional modules like HelloExecutor (a backdoor) and HelloBackdoor (a Rust-based implant).
26 distinct techniques documented for this family, organized by ATT&CK tactic.
HelloExecutor : backdoor permettant l’exécution de commandes ... HelloBackdoor ... supporte l’exécution de commandes
Detected TTPs: T1036 — Masquerading (service, description, and DLL masquerade as the legitimate Application Management)
Он ищет процесс, имя которого содержит строку svchost, а командная строка — строку netsvcs. Если такой процесс найден, загрузчик внедряет себя в целевой процесс с помощью функций NtWriteVirtualMemory и NtCreateThreadEx.
Detected TTPs: T1007 — System Service Discovery – “cmd” /c sc query UrBackupClientBackend
...с его помощью атакующие собирали информацию о пользователях, группах, сетевых настройках...
Detected TTPs: T1018 — Remote System Discovery – “cmd” /c ping mail.ru -n 2
HelloExecutor выполняет команды и используется для разведки, и с его помощью атакующие собирали информацию о пользователях...
HelloExecutor, a backdoor that can execute commands and conduct network reconnaissance on the host
Detected TTPs: T1049 — System Network Connections Discovery – “cmd” /c netstat -ano
...с его помощью атакующие собирали информацию о пользователях, группах...
HelloExecutor : backdoor permettant l’exécution de commandes et la reconnaissance réseau
Detected TTPs: T1083 — File and Directory Discovery – “cmd” /c dir temp*.tmp – “cmd” /c dir $temp\*.tmp – “cmd” /c dir amgmt*
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Component used to execute commands on infected systems and establish an SSH tunnel to attacker infrastructure.
A HelloNet component used to execute shell commands for reconnaissance.
An additional backdoor module delivered by HelloProxy in the HelloNet campaign.
Backdoor used for command execution and network reconnaissance on compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.