HelloNet is using ViPNet’s own update channel as the delivery path, so cleanup gets harder than removing a single implant. If the vendor maintenance path is compromised, normal software updates can keep putting the attacker back inside.
Kaspersky says the campaign is aimed at Russian government, energy, and transport organizations, and that detections and indicators of compromise have now been published. That moves the case from discovery into active hunting and takedown work.
The update system itself is the trust boundary at risk here, not just the endpoints that receive one bad package. Any environment that relies on vendor-managed updates should treat that channel as a standing persistence route once it is abused.
Hackers abuse ViPNet software to target Russian govt agencies
An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies.
HelloNet campaign: a threat via the ViPNet update system
We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).