Friday, September 11, 2026

Hackers Deploy New Malware Disguised as Networking Software Updates

A sophisticated backdoor has been uncovered targeting major organizations across Russia, including government bodies, financial institutions, and industrial sectors.

This malware, distributed under the guise of legitimate updates for ViPNet a widely used software suite for creating secure networks poses a significant threat to affected entities.

Our ongoing investigation into this cyber incident underscores the urgency of sharing preliminary findings to help at-risk organizations bolster their defenses against this insidious attack.

The malware’s distribution method, technical execution, and potential impact reveal a meticulously planned operation by advanced persistent threat (APT) actors.

Sophisticated Backdoor Targets Russian Organizations

The attackers have cleverly impersonated ViPNet updates, packaging their malicious payload within LZH archives that mimic the structure of authentic software updates.

These archives typically contain four key components: a configuration file named action.inf, a legitimate executable called lumpdiag.exe, a malicious executable disguised as msinfo32.exe, and an encrypted file housing the core payload with varying filenames.

According to the Report, the action.inf file instructs the ViPNet update service (itcsrvup64.exe) to execute lumpdiag.exe with a specific argument (–msconfig).

While lumpdiag.exe itself is benign, it is vulnerable to a path substitution technique, enabling the attackers to hijack the process and execute the malicious msinfo32.exe.

This loader then decrypts and loads the backdoor into memory, establishing a connection to a command-and-control (C2) server via TCP.

Once active, the backdoor empowers attackers to exfiltrate sensitive data, deploy additional malicious components, and maintain persistent access to compromised systems.

Kaspersky solutions have identified this threat as HEUR:Trojan.Win32.Loader.gen, and the ViPNet developer has confirmed targeted attacks on some users, issuing security updates and recommendations in response.

Multi-Layered Defense Against Evolving Threats

The complexity of this attack highlights the escalating sophistication of APT-driven cyberattacks, where adversaries exploit trusted software update mechanisms in unexpected ways to infiltrate high-value targets.

The ability to disguise malware as routine updates underscores the need for robust, multi-layered security architectures to counter such threats.

Defense-in-depth strategies, as implemented in products like Kaspersky NEXT, are critical for businesses to detect and mitigate similar attacks.

These solutions integrate advanced endpoint protection, threat intelligence, and proactive monitoring to safeguard against both known and emerging threats.

Organizations are urged to scrutinize update processes, verify the integrity of software patches, and deploy comprehensive security measures to prevent unauthorized access.

For actionable insights, indicators of compromise (IoCs) including specific hashes of the malicious msinfo32.exe and file paths where the malware resides have been identified.

These hashes include 018AD336474B9E54E1BD0E9528CA4DB5, 28AC759E6662A4B4BE3E5BA7CFB62204, and others, with malicious files often located in temporary update folders under %TEMP% or %PROGRAMFILES%.

Access to a full list of IoCs is available through Kaspersky Threat Intelligence services.

As this threat continues to evolve, staying informed and proactive is paramount for organizations aiming to shield themselves from such covert and damaging cyberattacks.

Find this News Interesting! Follow us on Google News, LinkedIn, & X to Get Instant Updates!

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News