🤚 The Open-Palm Breach Report
Kaspersky researchers have disclosed a sophisticated espionage campaign dubbed “HelloNet” that targets Russian government agencies, energy companies, transport networks, educational institutions, and logistics firms — by hiding inside the update mechanism of ViPNet, a security software suite that Russia’s own government certifies for protecting classified communications.
ViPNet, developed by Moscow-based InfoTeCS, is a comprehensive security product family providing VPN, endpoint protection, firewall, certificate management, and secure messaging. It is widely deployed across Russian government agencies and regulated industries precisely because the Russian authorities have certified it as trustworthy. The attackers chose to exploit this trust with surgical precision.
The attack works like this: a malicious DLL file (wtsapi32.dll, dubbed HelloInjector) is planted inside ViPNet’s Update System directory. When the system starts, the legitimate itcsrvup64.exe process sideloads the malicious DLL instead of the real one. HelloInjector then injects itself into svchost.exe, granting elevated privileges and persistence across reboots. From there, it deploys a modular toolkit of malware — all named with a cheerfulness that borders on psychological warfare.
👐 The Two-Handed Attribution Puzzle
The malware suite reads like a product catalog from hell:
- HelloProxy — contacts command-and-control servers for additional modules
- HelloExecutor — a backdoor enabling remote command execution and reconnaissance
- HelloCleaner — wipes ViPNet’s own logs to cover the attack’s tracks
- HelloBackdoor — a Rust-based implant supporting file transfers and command execution on ports 443 and 5003/5060
The campaign has been active since at least May 2026. Kaspersky’s attribution points — with the emphasis of someone backing away slowly from a claim — toward a Chinese-speaking APT group. The evidence: an unused string referencing sina.com (a Chinese web portal), a server hosted at China’s University of Science and Technology, and code similarities with known Chinese threat tools. Kaspersky rates this attribution at “low confidence” and explicitly warns that false flag operations cannot be ruled out.
Which is the intelligence community’s way of saying: “We think it might be China, but if you quote us on that and it turns out to be someone else wearing a very convincing accent, we did warn you.”
🌿 The Gentle Awakening
There is a particular flavor of irony in watching a nation’s government-certified security infrastructure become the attack vector. ViPNet’s entire value proposition is that Russian authorities have personally reviewed, approved, and mandated this software for protecting sensitive communications. The certification process is supposed to ensure that exactly this kind of compromise cannot happen. Instead, the certification created a monoculture — a single, trusted piece of software deployed uniformly across government, energy, and transport — and the attackers exploited the trust, not the code.
This is not the first time supply chain attacks have weaponized trust. SolarWinds taught the West this lesson in 2020. What makes HelloNet different is the geopolitical dimension: if Kaspersky’s tentative attribution is correct, this is a Chinese intelligence operation targeting Russian state infrastructure through Russian-certified security tools during a period when Moscow and Beijing are supposed to be strategic partners with a “no-limits” friendship.
Friendship, it appears, has limits. The limits are wherever the intelligence value exceeds the diplomatic cost of getting caught.
👑 The Gold-Leaf Reckoning
The HelloNet campaign is a textbook demonstration of why “government-certified” is a compliance checkbox, not a security guarantee. Every organization that deployed ViPNet because the authorities said it was safe is now learning that the same certification that made it mandatory also made it the single most efficient attack surface in the country. When everyone runs the same approved software, compromising that software compromises everyone.
Russia’s InfoTeCS has not publicly commented on the campaign. The affected sectors have not disclosed the scope of data exfiltration. And somewhere, in a server room that may or may not be at a Chinese university, the HelloBackdoor is running in Rust — because even state-sponsored threat actors have strong opinions about memory safety.
“The VPN that was certified to protect state secrets instead distributed them on a biweekly update schedule. The compliance department has questions but the answers are encrypted and the decryption key is in Beijing.” — The Slap of Wisdom Incident Response Team, writing this from a network that was at least compromised by a Western-certified product, which is somehow less embarrassing