DEV Community

Mark0
Mark0

Posted on

HelloNet campaign — new malicious modules launched through the ViPNet update system

Researchers have identified a new APT campaign named 'HelloNet' that targets large organizations in the government, energy, and logistics sectors. The attack is notable for its use of DLL sideloading via the ViPNet update system to deploy a sophisticated suite of custom malware, including loaders, proxies, and backdoors. Active since at least May 2026, the campaign leverages the trusted security software to gain persistence and move laterally within infected networks.

The technical toolkit includes 'HelloInjector' for process injection and 'HelloProxy', which intercepts system calls to hide network traffic and facilitate command execution. Analysts also discovered a Rust-based component called 'HelloBackdoor' and evidence of SSH tunneling using modified legitimate utilities. While strings in the code suggest a Chinese-speaking APT group, investigators remain cautious about potential false flags designed to complicate attribution.


Read Full Article

Top comments (0)