A recent cybersecurity report by Kaspersky describes the ongoing HelloNet campaign, linked to a suspected Chinese-speaking APT group, which targets large Russian organizations across various sectors, including government and industry. Active since May 2026, the attack utilizes the ViPNet update system to deliver malware, specifically through a malicious DLL (wtsapi32.dll) that exploits trusted processes. The malware toolkit includes tools for command execution and concealed communication.
Despite links to a potential Chinese origin, attribution remains cautious due to low confidence. No arrests have been made, and affected organizations are advised to implement security updates and monitor network traffic.