Researchers reported an active HelloNet intrusion campaign targeting large Russian organizations in government, energy, transport, education, logistics, and industrial sectors by abusing the InfoTeCS ViPNet Update System. The attackers gained persistence through DLL sideloading, placing a malicious wtsapi32.dll alongside itcsrvup64.exe in the ViPNet update directory, then injecting code into svchost.exe to launch a previously undocumented toolset: HelloInjector, HelloProxy, HelloExecutor, HelloCleaner, and the Rust-based HelloBackdoor. The malware supported reconnaissance, payload loading, proxying, file operations, and log wiping, including deletion of ViPNet traces to hinder investigation.
The operation has been active since at least May 2026 and used command infrastructure including 5.39.253[.]206 and 176.32.34[.]135, with operators also creating an SSH tunnel via a renamed PuTTY binary. Researchers said the backdoor listened on ports 5003 and 5060, used a custom handshake containing ASDFASFSAFASDF, and interfered with user-mode network monitoring by intercepting socket-related functions and IOCTLs. Attribution remains low confidence, with limited artifacts such as references to sina.com and use of a Chinese Rust crate mirror suggesting, but not proving, a Chinese-speaking APT actor; defenders were urged to review IoCs and closely monitor ViPNet-connected systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Securelist published a technical report describing the HelloNet campaign's use of DLL sideloading via a malicious wtsapi32.dll alongside itcsrvup64.exe, plus tools including HelloInjector, HelloProxy, HelloExecutor, HelloCleaner, and HelloBackdoor. The report also shared infrastructure details, detection guidance, and a low-confidence assessment linking the activity to an unknown Chinese-speaking APT group.
Researchers said the active APT campaign had been underway since at least May 2026, targeting large Russian organizations in government, energy, transport, education, logistics, and industrial sectors. The attackers abused the ViPNet update system to gain persistence and execute malware.
During an April 2025 cyberincident investigation, Kaspersky GReAT identified a backdoor targeting large Russian organizations and delivered via LZH archives disguised as ViPNet updates. The malware abused the ViPNet update service to launch a malicious loader and in-memory backdoor capable of C2 communications, file theft, and deploying additional components.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecyberveille.ch
Open sourcebleepingcomputer.com
Open sourcexakep.ru
Open sourcesecurelist.com
Open sourcesecurelist.ru
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.