{"id":763,"date":"2026-07-27T17:20:39","date_gmt":"2026-07-27T11:50:39","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=763"},"modified":"2026-08-18T17:24:30","modified_gmt":"2026-08-18T11:54:30","slug":"hellonet-malware-vipnet-dll-sideloading","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/hellonet-malware-vipnet-dll-sideloading\/","title":{"rendered":"HelloNet Malware Abuses ViPNet Through DLL Sideloading"},"content":{"rendered":"<h2>Introduction<\/h2>\n<p>HelloNet malware is part of a recently disclosed targeted APT campaign. It abuses the ViPNet networking suite in an attempt to establish Windows persistence through DLL sideloading. Public reporting has not identified a disclosed ViPNet vulnerability as the DLL sideloading mechanism. Instead, the attackers reportedly placed a malicious DLL in the local Update System directory.<\/p>\n<p>Researchers identified targeted infection attempts across Russia&#8217;s government, industrial, energy, transport, logistics, and education sectors. On an analyzed system, the attackers attempted to establish persistence through the ViPNet update component.<\/p>\n<p>Importantly, there is no public evidence that ViPNet&#8217;s update servers were compromised. Instead, the attackers reportedly abused trusted local application components, although the initial access method remains undisclosed. Therefore, organizations should strengthen endpoint detection, monitor trusted applications, and investigate unexpected DLL loading behavior.<\/p>\n<h3>Incident at a Glance<\/h3>\n<table style=\"font-weight: 400;\" data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1696\" aria-rowcount=\"11\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Category<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Details<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Campaign Name<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">HelloNet<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Incident Type<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Malware campaign<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Primary Technique<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">DLL sideloading<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Target Software<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">ViPNet networking suite<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Targeted Sectors<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Government, industrial, energy, transport,\u00a0logistics, and education organizations in Russia<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"7\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Persistence Method<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Malicious wtsapi32.dll loaded by the legitimate itcsrvup64.exe process<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"8\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Known Malware Components<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">HelloInjector,\u00a0HelloProxy,\u00a0HelloExecutor,\u00a0HelloCleaner,\u00a0HelloBackdoor<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"9\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Initial Access<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Not publicly disclosed<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"10\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">ViPNet Infrastructure Compromised?<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">No public evidence<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"11\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Threat Actor Attribution<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Not confirmed; attribution\u00a0remains\u00a0low confidence<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Who Could Be Affected?<\/h2>\n<p>Public reporting indicates that HelloNet malware targets organizations using the ViPNet networking suite. The campaign targets large Russian organizations across government, energy, transport, education, logistics, and industry.<\/p>\n<p>However, the defensive lessons extend beyond ViPNet users. The campaign shows how attackers abuse trusted Windows applications that load DLLs during startup. Therefore, enterprises should review similar execution paths in privileged software and automatic update mechanisms.<\/p>\n<p>In addition, organizations should strengthen endpoint detection and monitor trusted application directories. They should also investigate unexpected DLL loading and abnormal startup behavior. These measures help reduce the risk of similar attacks.<\/p>\n<h2>How the HelloNet ViPNet Attack Worked<\/h2>\n<p>Researchers observed the campaign as early as May 2026. For the observed persistence attempt, the attackers reportedly abused the local ViPNet Update System directory rather than a disclosed ViPNet vulnerability. They placed a malicious <code>wtsapi32.dll<\/code> file in the trusted location.<\/p>\n<p>When Windows starts the legitimate <code>itcsrvup64.exe<\/code> process, it loads the malicious DLL through <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-dll-side-loading\/\">DLL sideloading<\/a>. Consequently, HelloInjector executes and injects code into <code>svchost.exe<\/code>. The malware then attempts to maintain Windows persistence and loads additional malicious modules.<\/p>\n<p>The framework includes HelloInjector, HelloProxy, HelloExecutor, HelloCleaner, and the Rust-based HelloBackdoor. Together, these modules support command execution, reconnaissance, file transfer, and log cleanup.<\/p>\n<p>Importantly, public reporting does not indicate that ViPNet&#8217;s update infrastructure was compromised. Therefore, organizations should strengthen endpoint detection, monitor trusted application directories, and investigate unexpected DLL loading and process injection.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/xdr-and-zero-trust-150x150-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>XDR and Zero Trust: Securing Endpoints Together<\/h4><p>Learn how XDR and Zero Trust strengthen endpoint security through continuous visibility, investigation, and response.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/xdr-zero-trust-endpoint-security\/\" aria-label=\"XDR and Zero Trust: Securing Endpoints Together\"><\/a><\/div><\/div><\/div>\n<h2>What Is Confirmed and What Remains Unknown<\/h2>\n<h3>Confirmed Findings<\/h3>\n<p>Public reporting and technical analysis confirm these findings:<\/p>\n<ul>\n<li>Researchers named the campaign HelloNet.<\/li>\n<li>Researchers have observed the activity since May 2026.<\/li>\n<li>Researchers identified targeted infection attempts against Russian organizations in government, industry, energy, transport, logistics, and education.<\/li>\n<li>The attackers reportedly abused the local ViPNet Update System directory for DLL sideloading.<\/li>\n<li>The legitimate <code>itcsrvup64.exe<\/code> process loads the malicious <code>wtsapi32.dll<\/code> file.<\/li>\n<li>The malware framework includes HelloInjector, HelloProxy, HelloExecutor, HelloCleaner, and HelloBackdoor.<\/li>\n<\/ul>\n<h3>What Remains Unknown<\/h3>\n<p>Several details remain unconfirmed. Researchers have not disclosed the initial access vector. They have also not confirmed a compromise of ViPNet&#8217;s update infrastructure. Furthermore, they have not confirmed credential theft, ransomware, <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-data-exfiltration\/\">data exfiltration<\/a>, or lateral movement. Therefore, organizations should focus on the observed techniques, including DLL sideloading, Windows persistence, and trusted process abuse.<\/p>\n<h2>Why the HelloNet Campaign Matters for Enterprise Security<\/h2>\n<p>Although HelloNet currently targets Russian organizations, its techniques remain relevant to enterprises worldwide. For the observed persistence attempt, the attackers reportedly abused a trusted application rather than a disclosed ViPNet vulnerability. Consequently, the campaign shows how legitimate software can support malicious activity after an initial compromise.<\/p>\n<p>Furthermore, the incident highlights the need to monitor trusted applications. VPN clients, endpoint security tools, and enterprise software often run with elevated privileges. Therefore, attackers may abuse these applications to reduce detection.<\/p>\n<p>Organizations should strengthen endpoint detection by monitoring application directories, startup processes, and service behavior. They should also investigate unexpected DLL loading and <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-process-injection\/\">process injection<\/a>. In addition, they should verify application integrity and maintain approved software baselines.<\/p>\n<p>Ultimately, the campaign shows that trusted software deserves the same level of scrutiny as any other privileged application.<\/p>\n<h2>Why DLL Sideloading Remains a Threat<\/h2>\n<p>DLL sideloading can support execution, persistence, <a href=\"https:\/\/www.hexnode.com\/blogs\/what-is-privilege-escalation\/\">privilege escalation<\/a>, and defense evasion by abusing how applications load DLLs. If a legitimate application loads an attacker-controlled DLL, attackers can execute malicious code without modifying the signed executable.<\/p>\n<p>In the HelloNet ViPNet attack, the attackers reportedly placed a malicious wtsapi32.dll file in the local Update System directory. Consequently, the legitimate itcsrvup64.exe process loaded the DLL and executed HelloInjector.<\/p>\n<p>Therefore, organizations should strengthen endpoint detection by monitoring trusted application directories and unexpected DLL loading. They should also investigate process injection, unusual service creation, and suspicious outbound connections. In addition, they should review deviations from approved application baselines.<\/p>\n<p>Ultimately, behavioral monitoring can help identify trusted software abuse that signature-based controls may not detect.<\/p>\n<h2>How Hexnode UEM and XDR Help Reduce Risk<\/h2>\n<p>Campaigns like HelloNet malware highlight the need for strong endpoint management and rapid incident response. Although no platform prevents every attack, organizations can reduce risk through proactive device management and effective endpoint detection.<\/p>\n<h3>Hexnode UEM<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> helps IT teams centrally manage Windows devices. It also deploys approved applications, enforces security policies, and rolls out operating system updates. Furthermore, it helps maintain compliant devices and approved software baselines.<\/p>\n<h3>Hexnode XDR<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> helps security teams investigate suspicious endpoint activity. It also analyzes process execution, reviews historical endpoint events, isolates affected devices and terminates malicious processes during incident response. Consequently, security teams can investigate suspicious endpoint activity and respond to trusted software abuse through documented containment actions.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300-1.webp?format=webp\" class=\"resource-box__image\" alt=\"Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300-1.webp?format=webp 287w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300-1-96x100.webp?format=webp 96w\" sizes=\"auto, (max-width: 287px) 100vw, 287px\" title=\"Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Why XDR Is Stronger With UEM\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Learn how Hexnode XDR and UEM helps investigate endpoint threats and improve security operations across managed devices. \n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/why-xdr-is-stronger-with-uem\/'>\n                            Download the whitepaper\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>Key Takeaways<\/h2>\n<ul>\n<li>HelloNet malware abuses the local ViPNet Update System directory in an attempt to establish Windows persistence through DLL sideloading.<\/li>\n<li>Public reporting does not indicate that ViPNet&#8217;s update servers or software distribution infrastructure were compromised.<\/li>\n<li>The campaign shows how attackers abuse trusted software and legitimate Windows processes to reduce detection.<\/li>\n<li>Organizations should strengthen endpoint detection by monitoring trusted application directories, unexpected DLL loading, and process injection.<\/li>\n<li>Combining Hexnode UEM with Hexnode XDR helps organizations improve endpoint management, investigate threats, and support incident response.<\/li>\n<\/ul>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Is HelloNet a supply-chain attack?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Public reporting does not indicate that ViPNet&#8217;s update infrastructure was compromised. Instead, the attackers reportedly abused the local ViPNet Update System directory after an undisclosed initial compromise. Therefore, current evidence does not support classifying the activity as a traditional software supply-chain attack.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Why is DLL sideloading difficult to detect?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>DLL sideloading uses legitimate applications to load attacker-controlled libraries. Because the activity starts with a trusted executable, signature-based detection alone may miss it. Organizations should also monitor DLL loading, process injection, and abnormal application behavior.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Conclusion<\/h3>\n<p>The HelloNet malware campaign shows how attackers can abuse trusted software without relying on a disclosed <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-abuse-vipnet-software-to-target-russian-govt-agencies\/?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=5g_security\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">ViPNet vulnerability for DLL sideloading<\/a>. They reportedly used the local ViPNet Update System directory for DLL sideloading and attempted Windows persistence.<\/p>\n<p>Although several campaign details remain unconfirmed, the defensive lessons are clear. Therefore, organizations should strengthen endpoint detection, monitor trusted application directories, and investigate unexpected DLL loading. They should also validate software integrity across managed Windows devices.<\/p>\n<p>Ultimately, trusted software deserves continuous scrutiny. Combining endpoint management with timely endpoint investigation can support threat detection, incident response, and broader cyber resilience.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Turn Threat Intelligence into Action<\/h5><p>Get expert threat analysis, enterprise security, and actionable endpoint protection insights.<\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Try Hexnode Now<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction HelloNet malware is part of a recently disclosed targeted APT campaign. It abuses the&#8230;<\/p>\n","protected":false},"author":4,"featured_media":765,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[20,21],"class_list":["post-763","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-network-and-vpn","category-patch-management","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>HelloNet Malware Abuses ViPNet Through DLL Sideloading<\/title>\n<meta name=\"description\" content=\"HelloNet malware abuses the ViPNet Update System through DLL sideloading. Learn how the attack works and enterprise security lessons.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/hellonet-malware-vipnet-dll-sideloading\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"HelloNet Malware Abuses ViPNet Through DLL Sideloading\" \/>\n<meta property=\"og:description\" content=\"HelloNet malware abuses the ViPNet Update System through DLL sideloading. Learn how the attack works and enterprise security lessons.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/hellonet-malware-vipnet-dll-sideloading\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-27T11:50:39+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-18T11:54:30+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/HelloNet-Malware-Abuses-ViPNet-Through-DLL-Side-loading.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"754\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hellonet-malware-vipnet-dll-sideloading\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hellonet-malware-vipnet-dll-sideloading\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"HelloNet Malware Abuses ViPNet Through DLL Sideloading\",\"datePublished\":\"2026-07-27T11:50:39+00:00\",\"dateModified\":\"2026-08-18T11:54:30+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hellonet-malware-vipnet-dll-sideloading\\\/\"},\"wordCount\":1272,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hellonet-malware-vipnet-dll-sideloading\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/HelloNet-Malware-Abuses-ViPNet-Through-DLL-Side-loading.jpeg?format=webp\",\"articleSection\":[\"Network and VPN\",\"Patch Management\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hellonet-malware-vipnet-dll-sideloading\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hellonet-malware-vipnet-dll-sideloading\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hellonet-malware-vipnet-dll-sideloading\\\/\",\"name\":\"HelloNet Malware Abuses ViPNet Through DLL Sideloading\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hellonet-malware-vipnet-dll-sideloading\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hellonet-malware-vipnet-dll-sideloading\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/HelloNet-Malware-Abuses-ViPNet-Through-DLL-Side-loading.jpeg?format=webp\",\"datePublished\":\"2026-07-27T11:50:39+00:00\",\"dateModified\":\"2026-08-18T11:54:30+00:00\",\"description\":\"HelloNet malware abuses the ViPNet Update System through DLL sideloading. Learn how the attack works and enterprise security lessons.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hellonet-malware-vipnet-dll-sideloading\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hellonet-malware-vipnet-dll-sideloading\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hellonet-malware-vipnet-dll-sideloading\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/HelloNet-Malware-Abuses-ViPNet-Through-DLL-Side-loading.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/HelloNet-Malware-Abuses-ViPNet-Through-DLL-Side-loading.jpeg?format=webp\",\"width\":1340,\"height\":754,\"caption\":\"HelloNet Malware Abuses ViPNet Through DLL Side loading\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hellonet-malware-vipnet-dll-sideloading\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"HelloNet Malware Abuses ViPNet Through DLL Sideloading\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"HelloNet Malware Abuses ViPNet Through DLL Sideloading","description":"HelloNet malware abuses the ViPNet Update System through DLL sideloading. Learn how the attack works and enterprise security lessons.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/hellonet-malware-vipnet-dll-sideloading\/","og_locale":"en_US","og_type":"article","og_title":"HelloNet Malware Abuses ViPNet Through DLL Sideloading","og_description":"HelloNet malware abuses the ViPNet Update System through DLL sideloading. Learn how the attack works and enterprise security lessons.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/hellonet-malware-vipnet-dll-sideloading\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-07-27T11:50:39+00:00","article_modified_time":"2026-08-18T11:54:30+00:00","og_image":[{"width":1340,"height":754,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/HelloNet-Malware-Abuses-ViPNet-Through-DLL-Side-loading.jpeg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/hellonet-malware-vipnet-dll-sideloading\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/hellonet-malware-vipnet-dll-sideloading\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"HelloNet Malware Abuses ViPNet Through DLL Sideloading","datePublished":"2026-07-27T11:50:39+00:00","dateModified":"2026-08-18T11:54:30+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/hellonet-malware-vipnet-dll-sideloading\/"},"wordCount":1272,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/hellonet-malware-vipnet-dll-sideloading\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/HelloNet-Malware-Abuses-ViPNet-Through-DLL-Side-loading.jpeg?format=webp","articleSection":["Network and VPN","Patch Management"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/hellonet-malware-vipnet-dll-sideloading\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/hellonet-malware-vipnet-dll-sideloading\/","url":"https:\/\/www.hexnode.com\/threat-watch\/hellonet-malware-vipnet-dll-sideloading\/","name":"HelloNet Malware Abuses ViPNet Through DLL Sideloading","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/hellonet-malware-vipnet-dll-sideloading\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/hellonet-malware-vipnet-dll-sideloading\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/HelloNet-Malware-Abuses-ViPNet-Through-DLL-Side-loading.jpeg?format=webp","datePublished":"2026-07-27T11:50:39+00:00","dateModified":"2026-08-18T11:54:30+00:00","description":"HelloNet malware abuses the ViPNet Update System through DLL sideloading. Learn how the attack works and enterprise security lessons.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/hellonet-malware-vipnet-dll-sideloading\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/hellonet-malware-vipnet-dll-sideloading\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/hellonet-malware-vipnet-dll-sideloading\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/HelloNet-Malware-Abuses-ViPNet-Through-DLL-Side-loading.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/HelloNet-Malware-Abuses-ViPNet-Through-DLL-Side-loading.jpeg?format=webp","width":1340,"height":754,"caption":"HelloNet Malware Abuses ViPNet Through DLL Side loading"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/hellonet-malware-vipnet-dll-sideloading\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"HelloNet Malware Abuses ViPNet Through DLL Sideloading"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/763","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=763"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/763\/revisions"}],"predecessor-version":[{"id":770,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/763\/revisions\/770"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/765"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=763"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=763"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}