HelloProxy is a Windows in-memory malware component used in the HelloNet intrusion set against Russian organizations, particularly entities in government, energy, transport, education, logistics, and industrial sectors that use the ViPNet product suite. It functions as both a covert proxy and a loader for follow-on modules delivered from command-and-control infrastructure. In observed intrusions, HelloProxy was launched by the DLL-sideloaded first-stage loader HelloInjector after code injection into svchost.exe, forming part of a broader toolchain that also included HelloExecutor, HelloCleaner, and, in at least one case, the Rust-based HelloBackdoor.
Operationally, HelloProxy hides and relays attacker traffic while receiving additional payloads for in-memory execution. It hooks Windows networking functions and related socket-handling paths using Microsoft Detours, including interception of socket operations and device I/O control handling associated with network communications. This behavior is consistent with defense evasion and covert command-and-control support, and has been described as intended to hinder user-mode security monitoring of network connections. HelloProxy can also forward traffic between sockets, allowing it to act as an internal proxy for attacker communications.
As a loader, HelloProxy retrieves additional modules from the command server and executes them in memory. Observed follow-on payloads include HelloExecutor, used for command execution and reconnaissance, and HelloCleaner, used to remove ViPNet log data to conceal attacker activity. The broader campaign also deployed HelloBackdoor on at least one host for file transfer and command execution. HelloProxy therefore serves as a central staging and communications component within the malware ecosystem.
The malware has been associated with a cyber-espionage campaign active since at least May 2026 that abused the local ViPNet update mechanism through DLL sideloading. Attribution to a Chinese-speaking threat actor has been assessed only with low confidence and remains unconfirmed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The deployed malware, HelloProxy, contacts a command-and-control server for additional modules like HelloExecutor (a backdoor) and HelloBackdoor (a Rust-based implant).
5 distinct techniques documented for this family, organized by ATT&CK tactic.
SysExcSvc.dll, for receiving commands and exfiltrating their results back to Microsoft OneDrive cloud storage that's used as command-and-control (C2)
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hidden proxy and module loader that retrieves additional components from C2 and interferes with user-mode security solutions filtering network connections.
A HelloNet component that conceals network traffic, downloads additional payloads, hooks Windows socket functions, and listens for C2 commands on ports 5003 and 5060.
A proxy and loader payload used in the campaign that communicates with command-and-control infrastructure to retrieve additional malware modules.
In-memory payload that functions as a proxy and communicates with command-and-control infrastructure over ports 5003 and 5060.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.