Researchers have identified a new APT campaign named 'HelloNet' that targets large organizations in the government, energy, and logistics sectors. The attack is notable for its use of DLL sideloading via the ViPNet update system to deploy a sophisticated suite of custom malware, including loaders, proxies, and backdoors. Active since at least May 2026, the campaign leverages the trusted security software to gain persistence and move laterally within infected networks.
The technical toolkit includes 'HelloInjector' for process injection and 'HelloProxy', which intercepts system calls to hide network traffic and facilitate command execution. Analysts also discovered a Rust-based component called 'HelloBackdoor' and evidence of SSH tunneling using modified legitimate utilities. While strings in the code suggest a Chinese-speaking APT group, investigators remain cautious about potential false flags designed to complicate attribution.
Top comments (0)