Hackers Abuse ViPNet Software

Overview

Kaspersky researchers have uncovered a sophisticated cyber campaign dubbed HelloNet, where advanced threat actors are abusing the update mechanism of ViPNet software to infiltrate Russian organizations, including government agencies. ViPNet, developed by InfoTeCS, is widely used in Russia for secure networking, VPN, endpoint protection, and messaging — making it a high‑value target for attackers.

How the Attack Works

  • Attackers placed a malicious DLL file (wtsapi32.dll, nicknamed HelloInjector) inside the ViPNet Update System directory.
  • This DLL is sideloaded at startup via the legitimate itcsrvup64.exe process.
  • Once loaded, HelloInjector injects into svchost.exe, granting elevated privileges and persistence across reboots.
  • The malware then deploys additional payloads, including:
    • HelloProxy — acts as a proxy and loader, contacting C2 servers.
    • HelloExecutor — executes commands and performs network reconnaissance.
    • HelloCleaner — erases ViPNet log data to hide malicious activity.
    • HelloBackdoor — Rust‑based implant supporting file upload/download and command execution.

Attribution & Motives

  • Kaspersky tentatively attributes the campaign to a Chinese‑speaking APT group, citing weak indicators such as:
    • An unused string referencing sina.com.
    • A malware mirror hosted by the University of Science and Technology of China.
  • Attribution confidence is low, and researchers caution this could be a false flag operation.

Impacted Sectors

HelloNet has targeted organizations in:

  • Government
  • Energy
  • Transport
  • Education
  • Logistics

Given ViPNet’s certification for use in regulated environments, the campaign poses significant risks to critical infrastructure.

Defensive Recommendations

Kaspersky advises organizations running ViPNet software to:

  • Monitor traffic on ports 5003, 5060 (HelloProxy) and 443 (HelloBackdoor).
  • Audit update directories for unauthorized DLLs.
  • Strengthen endpoint monitoring to detect sideloading attempts.
  • Implement persistence detection for injected processes like svchost.exe.

Expert in the Cloud Insight

The HelloNet campaign highlights how attackers exploit trusted update mechanisms to bypass defenses. By embedding malicious DLLs into legitimate directories, they gain persistence and stealth. For defenders, the lesson is clear: treat update systems as high‑risk attack surfaces, enforce strict integrity checks, and monitor for anomalies in process behavior.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.