HelloInjector: Loader DLL Sideloaded via ViPNet Update
HelloInjector is a malicious loader DLL that is sideloaded by the ViPNet update binary itcsrvup64.exe. It injects itself into svchost.exe processes and…
HelloInjector is a malicious loader DLL that is sideloaded by the ViPNet update binary itcsrvup64.exe. It injects itself into svchost.exe processes and…
HelloProxy is a hidden proxy and loader used in the HelloNet attack. It loads additional modules from a C2 server and interferes…
HelloBackdoor is a Rust-based implant discovered in systems infected by the HelloNet attack. It enables file uploads and downloads to and from…
ViPNet is a product suite by InfoTeCS that provides secure communications. Its update mechanism was hijacked in the HelloNet attack to sideload…