{"id":3465,"date":"2025-04-23T10:04:16","date_gmt":"2025-04-23T10:04:16","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/04\/23\/hackers-attacking-organization-with-new-malware-mimic-as-networking-software-updates\/"},"modified":"2025-04-23T10:04:16","modified_gmt":"2025-04-23T10:04:16","slug":"hackers-attacking-organization-with-new-malware-mimic-as-networking-software-updates","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/04\/23\/hackers-attacking-organization-with-new-malware-mimic-as-networking-software-updates\/","title":{"rendered":"Hackers Attacking Organization With New Malware Mimic as Networking Software Updates"},"content":{"rendered":"<p>    Hackers Attacking Organization With New Malware Mimic as Networking Software Updates<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated backdoor targeting various large <a href=\"https:\/\/cybersecuritynews.com\/russian-seashell-blizzard-attacking-organizations\/\" target=\"_blank\" rel=\"noreferrer noopener\">Russian organizations<\/a> across government, finance, and industrial sectors has been uncovered during a cybersecurity investigation in April 2025. <\/p>\n<p>The malware, which masquerades as legitimate updates for ViPNet secure networking software, enables attackers to steal sensitive data and deploy additional malicious components to compromised systems.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Advanced Threat Landscape<\/strong><\/h2>\n<p>The backdoor specifically targets computers connected to ViPNet networks, a popular software suite used for creating secure networks in Russia. <\/p>\n<p>Cybersecurity experts have determined that the malware is distributed inside LZH archives structured to mimic legitimate ViPNet updates, containing a mix of legitimate and malicious files.<\/p>\n<p>\u201cThis attack demonstrates the increasing sophistication of threat actors who exploit trusted software update mechanisms,\u201d <a href=\"https:\/\/securelist.com\/new-backdoor-mimics-security-software-update\/116246\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">said<\/a> a senior cybersecurity analyst familiar with the investigation.<\/p>\n<p>The malicious archives contain several components: an action.inf text file, a legitimate lumpdiag.exe executable, a malicious msinfo32.exe executable, and an encrypted payload file with varying names across different archives. <\/p>\n<p>The attack leverages a path substitution technique\u2014when the ViPNet update service processes the archive, it executes the legitimate file with specific parameters, which then triggers the execution of the malicious msinfo32.exe file.<\/p>\n<p>Once active, the backdoor establishes connections with command and control (C2) servers via TCP protocols, enabling attackers to exfiltrate files from infected computers and execute additional malicious components.<\/p>\n<p>This discovery comes amid increasing cyber espionage activities. Recent reports have identified new <a href=\"https:\/\/cybersecuritynews.com\/how-to-track-advanced-persistent-threats\/\" target=\"_blank\" rel=\"noreferrer noopener\">advanced persistent threat (APT)<\/a> groups actively targeting government entities using sophisticated techniques that leverage cloud services and public platforms as command and control infrastructure.<\/p>\n<p>Similar patterns of state-sponsored hacking have been observed elsewhere, with cyberattacks linked to broader campaigns against critical institutions.<\/p>\n<p>ViPNet\u2019s developer has confirmed the targeted attacks against their users and has issued security updates and recommendations to mitigate the threat. <\/p>\n<p>Cybersecurity experts emphasize that as APT groups\u2019 tactics become increasingly complex, organizations must implement multi-layered defense strategies.<\/p>\n<p>Organizations using ViPNet networking solutions are strongly advised to:<\/p>\n<ul class=\"wp-block-list\">\n<li>Verify the authenticity of updates before installation.<\/li>\n<li>Implement strict access controls.<\/li>\n<li>Regularly monitor <a href=\"https:\/\/cybersecuritynews.com\/linux-malware-network-traffic-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">network traffic<\/a> for suspicious activities.<\/li>\n<li>Ensure security solutions detect threats like HEUR:Trojan.Win32.Loader.gen.<\/li>\n<\/ul>\n<p>Security researchers believe sharing these preliminary findings will help at-risk organizations take swift protective measures against this emerging threat that exploits trusted update mechanisms to penetrate secure networks.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Indicators of compromise<\/strong><\/h2>\n<p><strong>SHA256 hashes<\/strong><\/p>\n<pre class=\"wp-block-preformatted\">018AD336474B9E54E1BD0E9528CA4DB5<br>28AC759E6662A4B4BE3E5BA7CFB62204<br>77DA0829858178CCFC2C0A5313E327C1<br>A5B31B22E41100EB9D0B9A27B9B2D8EF<br>E6DB606FA2B7E9D58340DF14F65664B8<\/pre>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 93%,rgb(169,184,195) 100%)\"><strong><code>Malware Trends Report Based on 15000 SOC Teams Incidents, Q1 2025 out!-&gt;\u00a0<a href=\"https:\/\/any.run\/cybersecurity-blog\/malware-trends-q1-2025\/?utm_source=cyber-threat-intel_linkedin&amp;utm_medium=post&amp;utm_campaign=q1&amp;utm_content=blog&amp;utm_term=150425\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Get Your Free Copy<\/a><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/malware-networking-software-updates\/\">Hackers Attacking Organization With New Malware Mimic as Networking Software Updates<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Kaaviya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/malware-networking-software-updates\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Attacking Organization With New Malware Mimic as Networking Software Updates A sophisticated backdoor targeting various large Russian organizations across government, finance, and industrial sectors has been uncovered during a cybersecurity investigation in April 2025. The malware, which masquerades as legitimate updates for ViPNet secure networking software, enables attackers to steal sensitive data and deploy [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,258],"tags":[130],"class_list":["post-3465","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-malware","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3465"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=3465"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3465\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=3465"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=3465"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=3465"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}