View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Hackers abuse ViPNet update mechanism to target Russian government

🚨 ACTIVE EXPLOITATION

  • Hackers abuse ViPNet update mechanism to target Russian government agencies — BleepingComputer
    Hackers are exploiting ViPNet software updates to attack Russian government organizations.
    • Targets Russian organizations including government, energy, transport, education, and logistics sectors
    • Abuses ViPNet private networking product suite update mechanism to deploy malware
    • Malicious DLL (wtsapi32.dll, HelloInjector) sideloaded via legitimate ViPNet updater process
    • Malware includes proxy, backdoor, reconnaissance, and log-cleaning modules
    • Attributed with low confidence to a Chinese-speaking APT group based on weak indicators

🕵️ RESEARCH & DEEP DIVES

  • Hikvision cameras targeted by scans probing Intelligent Security API endpoints — SANS ISC
    Hikvision cameras are being scanned for their Intelligent Security API to identify vulnerable devices.
    • Applies to Hikvision cameras with the Intelligent Security API (ISAPI) since at least 2018
    • Scans target the /ISAPI/System/status endpoint to profile devices and check API support
    • ISAPI uses Basic or Digest authentication and supports XML/JSON messages
    • Encryption with AES is ineffective if Basic authentication is used due to exposed IV and password transmission
    • Scans likely aim to brute force passwords by identifying ISAPI-enabled devices

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check