Suspected Chinese APT Exploits ViPNet Software in Attacks on Russian Government
A sophisticated hacking campaign known as HelloNet targets Russian government agencies and critical infrastructure by abusing ViPNet, a widely used private networking software suite. According to researchers at Kaspersky, the campaign actively compromises organizations across the government, energy, transport, education, and logistics sectors. The attackers exploit ViPNet's trusted presence in regulated Russian environments to gain a persistent foothold in high-value targets.
The attackers deploy a malicious payload by placing a rogue file inside ViPNet's local update directory, which then loads at system startup through a legitimate ViPNet executable. This first-stage loader injects code into system processes, granting elevated privileges and enabling persistence across reboots. From there, the malware downloads additional modules including a proxy tool, a backdoor capable of file transfers and command execution, and a cleaner that removes ViPNet logs to cover the attackers' tracks.
Kaspersky tentatively attributes the campaign to an unidentified Chinese-speaking advanced persistent threat group, though the researchers note that this assessment rests on limited evidence. It remains unclear exactly how the attackers achieve initial access to plant the malicious file, and there is no indication that ViPNet's update infrastructure itself suffers a compromise. The campaign highlights how popular security software becomes an attractive attack vector when threat actors seek to infiltrate heavily protected networks.