HelloNet Targets Russian Agencies Through ViPNet Software
Cybersecurity

HelloNet Targets Russian Agencies Through ViPNet Software

Published:
Updated:

Kaspersky says a campaign it calls HelloNet has targeted Russian organizations in government, energy, transport, education and logistics since at least May. The attackers placed a malicious wtsapi32.dll file inside a computer's local ViPNet Update System directory, where the legitimate software sideloaded it during startup. The first-stage file, named HelloInjector by the researchers, launches HelloProxy to contact an attacker-controlled server and fetch more components. Those include the command-running HelloExecutor backdoor and HelloCleaner, which removes ViPNet log data. Kaspersky did not explain how the attackers gained their initial access, and it did not say ViPNet's update infrastructure itself was compromised. Why it matters: the distinction prevents an unsupported conclusion about a central supply-chain breach. The reported technique abused a local directory and trusted loading process, showing why defenders need to monitor files around legitimate security software as well as the software itself.

Source: BleepingComputer

Read our sourcing and corrections policy

Share:

Comments

Be the first to comment on this story!