Vendor
high
advisory
HelloNet Campaign Uses ViPNet Update System for Malicious Module Delivery
3 rules 11 TTPs 1 IOCAn unknown sophisticated threat actor is leveraging DLL sideloading within the ViPNet update system to deploy a multi-stage malware suite, including HelloInjector, HelloProxy, HelloExecutor, HelloCleaner, and HelloBackdoor, to establish persistence, exfiltrate data, and maintain covert access to large Russian organizations in government, energy, and other critical sectors.
ViPNet Update System
apt
dll-sideloading
persistence
proxy
c2
reconnaissance
data-exfiltration
russia
+1
3r
11t
1i
high
advisory
TrueConf Client Arbitrary Code Execution via Unverified Updates (CVE-2026-3502)
2 rules 1 TTP 1 CVE 1 IOCTrueConf Client downloads application updates without verifying integrity, allowing a network attacker to substitute a tampered payload, leading to arbitrary code execution.
TrueConf Server +1
cve-2026-3502
trueconf
rce
update
2r
1t
1c
1i
updated