HelloNet is using ViPNet’s own update channel as the delivery path, so cleanup gets harder than removing a single implant. If the vendor maintenance path is compromised, normal software updates can keep putting the attacker back inside.
Kaspersky says the campaign is aimed at Russian government, energy, and transport organizations, and that detections and indicators of compromise have now been published. That moves the case from discovery into active hunting and takedown work.
The update system itself is the trust boundary at risk here, not just the endpoints that receive one bad package. Any environment that relies on vendor-managed updates should treat that channel as a standing persistence route once it is abused.