HelloNet campaign: a threat via the ViPNet update system
Reported 16 Jul 2026 by otx · Severity: medium
An active APT campaign discovered in May 2026 exploits the ViPNet update system to deploy previously unknown tooling against large Russian organizations. Attackers achieve persistence through DLL sideloading, placing malicious wtsapi32.dll in ViPNet directories. The campaign empl