At a glance
| Actor / group | Suspected Chinese-speaking APT group (low confidence) |
| Activity type | Cyberespionage using malicious ViPNet update modules |
| Targets / victims | Large Russian government, energy, transport, education, logistics, and industrial organizations |
| Scale | Multiple large organizations; active since at least May 2026 |
| Status | Ongoing; no arrests; vendor InfoTeCS shipped fixes |
| Source | Kaspersky GReAT (Securelist) |
TL;DR
Kaspersky found a new HelloNet campaign that pushes malware through the ViPNet update system. The attackers target large Russian organizations across several sectors. Researchers link the operation to a suspected Chinese-speaking group, yet only with low confidence.
What happened
Kaspersky’s GReAT team spotted the intrusions in May 2026. The HelloNet campaign is still active today. First, attackers plant a malicious file named wtsapi32.dll inside a ViPNet update folder. Then Windows starts, and the trusted update executable itcsrvup64.exe loads the rogue DLL. This DLL sideloading trick hands the attackers a quiet foothold. Kaspersky says the implants were “launched through the ViPNet update system,” a suite for building secure networks.
Inside the malware toolkit
The operation relies on several custom tools. HelloInjector loads code into the svchost.exe process. Next, HelloProxy hides traffic and pulls down more payloads. To stay quiet, it hooks Windows socket functions with the Microsoft Detours library. It also listens on ports 5003 and 5060 for commands from the control server. HelloExecutor then runs shell commands for reconnaissance. Meanwhile, HelloCleaner wipes ViPNet log files to cover tracks. On one host, researchers also found HelloBackdoor, a Rust program built for file transfers.
How the attackers moved
The intruders mapped each network before going deeper. They listed ViPNet folders and checked logged-in users. They also built an SSH tunnel using a renamed copy of PuTTY. Renaming PuTTY to frontpage.exe helped that tunnel blend in. It then reached an external command server over an unusual port. As a result, stolen data and remote access flowed through trusted-looking traffic.
Who is behind the HelloNet campaign
Attribution stays cautious for now. Analysts spotted a stray string pointing to sina.com, a popular Chinese news portal. They also traced Rust packages to a Chinese download mirror. However, these clues could be planted false flags. Therefore, Kaspersky ties the HelloNet campaign to a suspected Chinese-speaking APT group with low confidence.
Impact and scale
The victims span government, energy, transport, education, logistics, and industry. Each is a large Russian organization, which raises the espionage stakes. This is also not the first ViPNet abuse. Last year, Kaspersky found a backdoor that mimicked ViPNet updates. Reassuringly, Kaspersky reports its products “detect such activity and prevent infection attempts at all stages.”
What comes next and how to stay protected
So far, no arrests have surfaced. The vendor, InfoTeCS, urged customers to update ViPNet Client and ViPNet Administrator to fixed versions. After updating, admins should scan their systems with the published YARA rules. Kaspersky also advises close watch over any workstation that runs ViPNet. In particular, monitor traffic on ports 5003 and 5060 for signs of compromise. If a scan flags anything odd, contact vendor support quickly.
Detection tips
Start with the update folder itself. Flag any wtsapi32.dll that lands beside itcsrvup64.exe. Watch for a stray file at C:\Users\Public\tesh4RPC.txt, since HelloProxy writes there. Also hunt for renamed PuTTY binaries under the public music folder. Finally, block outbound SSH to unknown hosts on odd ports.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.