Intel Node
HelloNet campaign — new malicious modules launched through the ViPNet update system
Source excerpt · The upstream feed supplied only part of this article.Read the original source →
We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).
UPD 16. 07. 2026: Added rules to protect companies using our SIEM system Kaspersky SIEM, and listed events for developing custom detection rules or conducting Threat hunting. UPD 16. 07. 2026: Added detection of the malicious activity using Kaspersky Managed Detection and Response. UPD 16. 07. 2026: Added detection rules and examples using KEDR Expert. UPD 16. 07. 2026: Added detection of the malicious campaign in network traffic using Kaspersky Anti Targeted Attack (KATA) with the NDR module. UPD 16. 07. 2026: Updated the list of Indicators of Compromise (IoCs) and TTPs.
We discovered a new APT attack using previously unknown tooling, which started at least in May 2026 and remains active at the time of publication. It is notable in that the implants used during it were launched through the ViPNet update system (a software suite for creating secure networks).