ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)
A campaign called HelloNet abuses ViPNet's update mechanism to target Russian government agencies. Attackers place a malicious DLL, HelloInjector, in the ViPNet Update System directory for sideloading. The payload deploys HelloProxy, HelloExecutor, HelloCleaner, and HelloBackdoor. Kaspersky attributes the campaign to an unidentified Chinese-speaking APT group with low confidence.
Tap to vote and see what everyone thinks.
Summary by ByteBrief