HelloCleaner is a Windows malware component used in the HelloNet intrusion set to erase ViPNet software log data and reduce forensic visibility after compromise. It has been observed in campaigns targeting large Russian organizations, including entities in government, energy, transport, education, logistics, industrial, IT, electronics, instrumentation, and software development sectors. The broader activity abuses the ViPNet update mechanism through DLL sideloading of a malicious loader, after which additional modules are deployed for proxying, command execution, reconnaissance, tunneling, and backdoor access.
Within this toolchain, HelloCleaner functions as a cleanup and anti-forensics module rather than a primary access implant. Its role is to remove ViPNet log files and conceal attacker actions on infected systems, supporting post-compromise stealth and defense evasion. It has been associated with companion components including HelloInjector, HelloProxy, HelloExecutor, and in some cases HelloBackdoor. Reporting has tentatively linked the overall campaign with low confidence to an unidentified Chinese-speaking threat actor, though that attribution remains uncertain and possible false-flag activity has been noted.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Он ищет процесс, имя которого содержит строку svchost, а командная строка — строку netsvcs. Если такой процесс найден, загрузчик внедряет себя в целевой процесс с помощью функций NtWriteVirtualMemory и NtCreateThreadEx.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Component designed to remove ViPNet log files and erase forensic evidence.
A HelloNet component that deletes ViPNet log files to reduce forensic visibility and cover attacker tracks.
A campaign tool used to erase ViPNet log data, likely for anti-forensics and cleanup.
Utility used to delete ViPNet logs in order to remove forensic traces and hinder detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.