
HelloNet Targets Russian Agencies Through ViPNet Software
Kaspersky says a campaign it calls HelloNet has targeted Russian organizations in government, energy, transport, education and logistics since at least May. The attackers placed a malicious wtsapi32.dll file inside a computer's local ViPNet Update System directory, where the legitimate software sideloaded it during startup. The first-stage file, named HelloInjector by the researchers, launches HelloProxy to contact an attacker-controlled server and fetch more components. Those include the command-running HelloExecutor backdoor and HelloCleaner, which removes ViPNet log data. Kaspersky did not explain how the attackers gained their initial access, and it did not say ViPNet's update infrastructure itself was compromised. Why it matters: the distinction prevents an unsupported conclusion about a central supply-chain breach. The reported technique abused a local directory and trusted loading process, showing why defenders need to monitor files around legitimate security software as well as the software itself.
Read our sourcing and corrections policy
Related News
Comments
Be the first to comment on this story!


