An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies.

Dubbed HelloNet, the campaign has been active since at least May, deploying a malicious payload that acts as a proxy and loader for additional malware.

According to Kaspersky researchers, HelloNet has impacted organizations in the government, energy, transport, education, and logistics sectors.

ViPNet update abuse

ViPNet is a family of Russian information-security products developed by InfoTeCS, providing VPN, endpoint, and network access protection, firewall, certificate management, centralized administration, and secure messaging and file transfer.