ViPNet as transport for malware 📦

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
PT ESC specialists have recorded signs of attackers carrying out an attack through the standard functionality of the ViPNet MFTP service. As of the publication of this post, the attack timeline covers a period of at least June 1 to July 14, 2026, and its scope covers at least 8 organizations.
If you suspect an incident — write to us, and we will help with the investigation.
How the attack occurs
Through the basic functionality of the MFTP transport protocol, the attackers transmit between clients an envelope file (.ctl) containing a malicious library wtsapi32.dll, which is loaded by the executable file Itcsrvup64.exe (a component of the ViPNet software update service) using the DLL Hijacking technique and is saved to the file system using the Path Traversal technique at the path:
C:\ProgramData\InfoTeCS\<9-digit_device_identifier>\./../../../program files (x86)/infotecs/vipnet update system/wtsapi32.dll
wtsapi32.dll
The malware is a loader that stores in the .data section an executable file in the form of a DLL library with modified magic bytes in the header.
The malware checks the launch context. If launched in the context of any process other than svchost.exe, it finds a running instance of the svchost.exe process with the netsvcs parameter in the command line and injects the specified library into it.
Main functionality of the malware:
- operating in proxy server mode to redirect network traffic;
- loading additional DLL libraries into the address space;
- executing the loaded libraries.
Command processing is based on an IOCTL request dispatcher that manages a table of active connections by intercepting WinAPI functions:
NtDeviceIoControlFileclosesocketshutdown
Using the Detours library, the table:
- blocks premature closure of network sockets;
- processes the operation code
AFD_GET_TDI_HANDLES (0x12037)to register a new socket; - processes
AFD_RECV (0x12017)to begin processing incoming traffic.
Descriptors are saved into a table (8344 bytes per entry).
When processing code 0x12017, the malware writes the thread and process identifiers to the file:
C:\Users\Public\tesh4RPC.txt
in the format:
threadid: pid=
In parallel, the malware deploys a TCP server on the ports:
50035060
A separate processing thread is created for each client.
After a successful “handshake”:
- two bytes
0x0502are sent; - a string is expected:
ASDFASFSAFASDF
Next:
- messages of the form
:<data>are used to create new sockets and proxy traffic; - if an executable file arrives, it is loaded into the process memory and launched in a separate thread.
SetupChk.exe
Separately, it is worth noting an episode at the end of May 2026 — an update package in the form of a .lzh archive was delivered to ViPNet client devices, containing:
SetupCheck.dllSetupChk.exe
The malware reads information from the Windows registry:
SOFTWARE\Wow6432Node\InfoTeCS\ITCSShared\AuthInfo
After which it determines the client version by the key (expects version 4.5):
SOFTWARE\Infotecs\FeaturesAndComponents\Monitor_Feature
Functionality of the malware:
1️⃣ Clearing InfoTeCS logs:
C:\ProgramData\InfoTeCS\UpdateSystemData\UpdateSystem.JournalC:\ProgramData\InfoTeCS\UpdateSystemData\updateservice.log.txtC:\ProgramData\InfoTeCS\Mftp\mftp.debug.logC:\Program Files (x86)\InfoTeCS\ViPNet Client\mftp.log
2️⃣ Collecting system information:
- processes;
- network connections;
- installed software;
3️⃣ Generating a malicious envelope m02smnrf.ctl.
During the investigation, the following were also discovered:
Configuration of the discovered ShadowRelay instance:
{
"mode": "client",
"proto": "tcp",
"svri": "154.89.152.59",
"svrp": 443,
"reconnintv": 459,
"enctype": "aes",
"aeskey": "]zf,.Hso'!x3|ezz/hzHzxa(P=x.bB.r",
"rsapubkey": "not set",
"rsaprikey": "not set",
"antidebug": 1,
"autodelete": 0,
"autostart": 0,
"portreuse": 0,
"envpara": "3ff18683a02d3aefab2f",
"targetprocess": "",
"usehttp": 0,
"servicename": "svcsvc",
"servicedesc": "OneDrive client application",
"beattimeout": 65
}
Detection method
To check whether the incident occurred, it is recommended to run:
Get-ChildItem -Path "C:\ProgramData\Infotecs\Mftp" -File -Recurse |
Select-String -Pattern "\.dll|\.\/\.\.\/\.\.\/\.\.\/"
Detection example:
C:\ProgramData\Infotecs\Mftp\mftp.debug.log:166742:REDACTED [REDACTED]: File C:\ProgramData\InfoTeCS\REDACTED\./../../../program files (x86)/infotecs/vipnet update system/wtsapi32.dll with keepFlag=0 and fileSize=219136
To check whether a malicious update was received:
Get-ChildItem -Path "C:\ProgramData\Infotecs\UpdateSystemData" -File -Recurse |
Select-String -Pattern "/driv_fs/"
Example result:
C:\ProgramData\Infotecs\UpdateSystemData\updateservice.log.lo1:9157:REDACTED: Extracting file update/driv_fs/setup.exe.config
C:\ProgramData\Infotecs\UpdateSystemData\updateservice.log.lo1:9158:REDACTED: Extracting file update/driv_fs/setupcheck.dll
C:\ProgramData\Infotecs\UpdateSystemData\updateservice.log.lo1:9159:REDACTED: Extracting file update/driv_fs/setupchk.exe
💡 MaxPatrol SIEM and MaxPatrol EDR detect exploitation of the vulnerability in ViPNet with the DLL_Side_Loading rule. MaxPatrol VM detects the flaw and provides recommendations for promptly closing it.
Recommendations
Apply the updates: ViPNet Client 4 version 4.5.3 build 65211 and higher, version 4.5.5 build 24733, which will become available soon, as well as ViPNet Administrator version 4.6.11.5113 and higher.
And if that is not possible, then to neutralize the threats it is necessary to:
- stop the ViPNet update system service;
- disable the service on every node where it is installed;
- prohibit automatic startup.
Option A. Via the graphical interface
Win + Rservices.msc- Find the ViPNet Update System service.
- Open its properties.
- Select the startup type Disabled.
- Click Stop.
- Click Apply and OK.
Option B. Via PowerShell
# Stop the service
Stop-Service -Name "itcsrvup" -Force
# Disable the service
Set-Service -Name "itcsrvup" -StartupType Disabled
Additionally, it is necessary to disable the MFTP service on HW coordinators and the xFirewall MFTP service using the following command:
mftp stop
It is also important to:
- monitor for the appearance of indicators of compromise;
- update ViPNet software components in a timely manner.
IoC's
Malware samples
| File name | SHA-256 / Hash |
|---|---|
| SetupCheck.dll | 8b089163edb36e7a65baccb8ab317895162057a1acb2a5dc59dffd3d03c7cdb5 |
| SetupChk.exe | 7d0e3efe656a28251e6460af1baa489ea6a07053a4bc6578edba659ab28afd5d |
| Rngpkcsmgr.exe | — |
| Rngsdkcfg.exe | 68b4c76a2280e3c31130d4de12b12dfd479a476f347f5b4a58cb2483d74aba7e |
| wtsapi32.dll | 841aea34ca81577468c3a5ab3039370a83cd9dca7ad95af092a9a22b661ec3f1 |
| wtsapi32.dll | b8192bb83d5d33bf6e32879d2bfb783cbbd3df6ded23206867161f091897d4c4 |
| wtsapi32.dll | ffdc194775b2904564bbbd1cf0eb01d1a01f83ef5197d1612b6e2d69de7a4732 |
| — | 5e462c89def65cbdddbd3ae78a1e281400199143af330e976384416cf466b9d8 |
| m02smnrf.ctl | — |
| mocdng.dll | e19adeaaa9f19f2cf0460d9f61ff54e90b5de30c2cd8d1db04fdf8afaa243295 |
| update.bat | bc34b8d8bc320c5fa1d280e6a7ca876950047d2ee0520b0f5e49bb49481e987d |
| info.bat | 4921e2f1fb2ef81862e6727bbac653c8e66fd2132529205798788981905151fc |
| odcitvmd.dll | 82dd0af848118009709639d75ca43bd9 |
| msvdplib.dll | 5384157b66e9976c9a1c8429d236b512 |
| mustd.exe | 13d8d4f4fa483111e4372a6925d24e28f3be082a2ea8f44304384982bd692ec9 |
| Diagnosis.exe | c2f2a6a28d41ac243455a30c4ab39af13ed647e43d00eb69c14482e9314e9140 |
File indicators
C:\Users\Public\tesh4RPC.txtC:\Users\Public\ntusers.logsC:\ProgramData\InfoTeCS\<9-digit_device_identifier>\ccc\wtsapi32.up1C:\Users\Public\music\info.batC:\Users\Public\music\up.zipC:\Users\Public\music\res.logC:\Users\Public\music\mustd.exe
Services
- Network Monitor Serial Service
- OneDrive client application
- Ntmssvc
- Svcsvc
Network indicators
| IP | Country | Organization |
|---|---|---|
123.58.203.41 |
India | AS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED |
154.89.152.59 |
Malaysia | AS139923 ABCCLOUD SDN.BHD. |
31.57.35.21 |
United Kingdom | AS21859 Zenlayer Inc |
5.39.253.206 |
Kazakhstan | AS49791 Newserverlife LLC |
We are monitoring the development of events and will update the material on the website as new details emerge.
#dfir #ir #ti
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…






