HelloNet campaign: a threat via the ViPNet update system

Reported 16 Jul 2026 by otx · Severity: medium

An active APT campaign discovered in May 2026 exploits the ViPNet update system to deploy previously unknown tooling against large Russian organizations. Attackers achieve persistence through DLL sideloading, placing malicious wtsapi32.dll in ViPNet directories. The campaign empl