Skip to content
Tech News
← Back to articles

Hackers abuse ViPNet software to target Russian govt agencies

read original more articles
Why This Matters

The abuse of ViPNet software by hackers highlights the vulnerabilities in widely used security tools, especially those trusted by government and high-value organizations. This incident underscores the importance of securing update mechanisms and monitoring for sophisticated supply chain attacks to protect critical infrastructure and sensitive data.

Key Takeaways

An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies.

Dubbed HelloNet, the campaign has been active since at least May, deploying a malicious payload that acts as a proxy and loader for additional malware.

According to Kaspersky researchers, HelloNet has impacted organizations in the government, energy, transport, education, and logistics sectors.

ViPNet update abuse

ViPNet is a family of Russian information-security products developed by InfoTeCS, providing VPN, endpoint, and network access protection, firewall, certificate management, centralized administration, and secure messaging and file transfer.

The tool is commonly used in Russia, where it is certified by the authorities for use in government and other regulated environments.

Due to its market reach in Russia, especially among high-value organizations, it has been targeted often by hackers. In April, 2025, Kaspersky reported that threat actors impersonated a ViPNet update in attacks.

In the latest campaign, attackers placed a malicious file (wtsapi32.dll, dubbed HelloInjector) inside the local ViPNet Update System directory to be sideloaded at system startup via the legitimate itcsrvup64.exe.

This DLL is the first-stage loader that injects into the svchost.exe process, granting next-stage payloads elevated privileges on Windows and persistence across reboots.

Kaspersky does not describe exactly how the attackers gained initial access to perform this file change, nor do they claim that ViPNet’s update infrastructure itself was compromised.

... continue reading