[ << ALL_FEED ]

ViPNet as transport for malware 📦

More in General

PT ESC specialists have recorded signs of attackers carrying out an attack through the standard functionality of the ViPNet MFTP service. As of the publication of this post, the attack timeline covers a period of at least June 1 to July 14, 2026, and its scope covers at least 8 organizations.

If you suspect an incident — write to us, and we will help with the investigation.

How the attack occurs

Through the basic functionality of the MFTP transport protocol, the attackers transmit between clients an envelope file (.ctl) containing a malicious library wtsapi32.dll, which is loaded by the executable file Itcsrvup64.exe (a component of the ViPNet software update service) using the DLL Hijacking technique and is saved to the file system using the Path Traversal technique at the path:

C:\ProgramData\InfoTeCS\<9-digit_device_identifier>\./../../../program files (x86)/infotecs/vipnet update system/wtsapi32.dll

wtsapi32.dll

The malware is a loader that stores in the .data section an executable file in the form of a DLL library with modified magic bytes in the header.

The malware checks the launch context. If launched in the context of any process other than svchost.exe, it finds a running instance of the svchost.exe process with the netsvcs parameter in the command line and injects the specified library into it.

Main functionality of the malware:

  • operating in proxy server mode to redirect network traffic;
  • loading additional DLL libraries into the address space;
  • executing the loaded libraries.

Command processing is based on an IOCTL request dispatcher that manages a table of active connections by intercepting WinAPI functions:

  • NtDeviceIoControlFile
  • closesocket
  • shutdown

Using the Detours library, the table:

  • blocks premature closure of network sockets;
  • processes the operation code AFD_GET_TDI_HANDLES (0x12037) to register a new socket;
  • processes AFD_RECV (0x12017) to begin processing incoming traffic.

Descriptors are saved into a table (8344 bytes per entry).

When processing code 0x12017, the malware writes the thread and process identifiers to the file:

C:\Users\Public\tesh4RPC.txt

in the format:

threadid: pid=

In parallel, the malware deploys a TCP server on the ports:

  • 5003
  • 5060

A separate processing thread is created for each client.

After a successful “handshake”:

  • two bytes 0x0502 are sent;
  • a string is expected:
ASDFASFSAFASDF

Next:

  • messages of the form :<data> are used to create new sockets and proxy traffic;
  • if an executable file arrives, it is loaded into the process memory and launched in a separate thread.

SetupChk.exe

Separately, it is worth noting an episode at the end of May 2026 — an update package in the form of a .lzh archive was delivered to ViPNet client devices, containing:

  • SetupCheck.dll
  • SetupChk.exe

The malware reads information from the Windows registry:

SOFTWARE\Wow6432Node\InfoTeCS\ITCSShared\AuthInfo

After which it determines the client version by the key (expects version 4.5):

SOFTWARE\Infotecs\FeaturesAndComponents\Monitor_Feature

Functionality of the malware:

1️⃣ Clearing InfoTeCS logs:

  • C:\ProgramData\InfoTeCS\UpdateSystemData\UpdateSystem.Journal
  • C:\ProgramData\InfoTeCS\UpdateSystemData\updateservice.log.txt
  • C:\ProgramData\InfoTeCS\Mftp\mftp.debug.log
  • C:\Program Files (x86)\InfoTeCS\ViPNet Client\mftp.log

2️⃣ Collecting system information:

  • processes;
  • network connections;
  • installed software;

3️⃣ Generating a malicious envelope m02smnrf.ctl.

During the investigation, the following were also discovered:

  • the loader Donnect (mocdng.dll);
  • the backdoor ShadowRelay (Diagnosis.exe).

Configuration of the discovered ShadowRelay instance:

{
  "mode": "client",
  "proto": "tcp",
  "svri": "154.89.152.59",
  "svrp": 443,
  "reconnintv": 459,
  "enctype": "aes",
  "aeskey": "]zf,.Hso'!x3|ezz/hzHzxa(P=x.bB.r",
  "rsapubkey": "not set",
  "rsaprikey": "not set",
  "antidebug": 1,
  "autodelete": 0,
  "autostart": 0,
  "portreuse": 0,
  "envpara": "3ff18683a02d3aefab2f",
  "targetprocess": "",
  "usehttp": 0,
  "servicename": "svcsvc",
  "servicedesc": "OneDrive client application",
  "beattimeout": 65
}

Detection method

To check whether the incident occurred, it is recommended to run:

Get-ChildItem -Path "C:\ProgramData\Infotecs\Mftp" -File -Recurse |
Select-String -Pattern "\.dll|\.\/\.\.\/\.\.\/\.\.\/"

Detection example:

C:\ProgramData\Infotecs\Mftp\mftp.debug.log:166742:REDACTED [REDACTED]: File C:\ProgramData\InfoTeCS\REDACTED\./../../../program files (x86)/infotecs/vipnet update system/wtsapi32.dll with keepFlag=0 and fileSize=219136

To check whether a malicious update was received:

Get-ChildItem -Path "C:\ProgramData\Infotecs\UpdateSystemData" -File -Recurse |
Select-String -Pattern "/driv_fs/"

Example result:

C:\ProgramData\Infotecs\UpdateSystemData\updateservice.log.lo1:9157:REDACTED: Extracting file update/driv_fs/setup.exe.config

C:\ProgramData\Infotecs\UpdateSystemData\updateservice.log.lo1:9158:REDACTED: Extracting file update/driv_fs/setupcheck.dll

C:\ProgramData\Infotecs\UpdateSystemData\updateservice.log.lo1:9159:REDACTED: Extracting file update/driv_fs/setupchk.exe

💡 MaxPatrol SIEM and MaxPatrol EDR detect exploitation of the vulnerability in ViPNet with the DLL_Side_Loading rule. MaxPatrol VM detects the flaw and provides recommendations for promptly closing it.

Recommendations

Apply the updates: ViPNet Client 4 version 4.5.3 build 65211 and higher, version 4.5.5 build 24733, which will become available soon, as well as ViPNet Administrator version 4.6.11.5113 and higher.

And if that is not possible, then to neutralize the threats it is necessary to:

  • stop the ViPNet update system service;
  • disable the service on every node where it is installed;
  • prohibit automatic startup.

Option A. Via the graphical interface

  1. Win + R
  2. services.msc
  3. Find the ViPNet Update System service.
  4. Open its properties.
  5. Select the startup type Disabled.
  6. Click Stop.
  7. Click Apply and OK.

Option B. Via PowerShell

# Stop the service
Stop-Service -Name "itcsrvup" -Force

# Disable the service
Set-Service -Name "itcsrvup" -StartupType Disabled

Additionally, it is necessary to disable the MFTP service on HW coordinators and the xFirewall MFTP service using the following command:

mftp stop

It is also important to:

  • monitor for the appearance of indicators of compromise;
  • update ViPNet software components in a timely manner.

IoC's

Malware samples

File name SHA-256 / Hash
SetupCheck.dll 8b089163edb36e7a65baccb8ab317895162057a1acb2a5dc59dffd3d03c7cdb5
SetupChk.exe 7d0e3efe656a28251e6460af1baa489ea6a07053a4bc6578edba659ab28afd5d
Rngpkcsmgr.exe —
Rngsdkcfg.exe 68b4c76a2280e3c31130d4de12b12dfd479a476f347f5b4a58cb2483d74aba7e
wtsapi32.dll 841aea34ca81577468c3a5ab3039370a83cd9dca7ad95af092a9a22b661ec3f1
wtsapi32.dll b8192bb83d5d33bf6e32879d2bfb783cbbd3df6ded23206867161f091897d4c4
wtsapi32.dll ffdc194775b2904564bbbd1cf0eb01d1a01f83ef5197d1612b6e2d69de7a4732
— 5e462c89def65cbdddbd3ae78a1e281400199143af330e976384416cf466b9d8
m02smnrf.ctl —
mocdng.dll e19adeaaa9f19f2cf0460d9f61ff54e90b5de30c2cd8d1db04fdf8afaa243295
update.bat bc34b8d8bc320c5fa1d280e6a7ca876950047d2ee0520b0f5e49bb49481e987d
info.bat 4921e2f1fb2ef81862e6727bbac653c8e66fd2132529205798788981905151fc
odcitvmd.dll 82dd0af848118009709639d75ca43bd9
msvdplib.dll 5384157b66e9976c9a1c8429d236b512
mustd.exe 13d8d4f4fa483111e4372a6925d24e28f3be082a2ea8f44304384982bd692ec9
Diagnosis.exe c2f2a6a28d41ac243455a30c4ab39af13ed647e43d00eb69c14482e9314e9140

File indicators

  • C:\Users\Public\tesh4RPC.txt
  • C:\Users\Public\ntusers.logs
  • C:\ProgramData\InfoTeCS\<9-digit_device_identifier>\ccc\wtsapi32.up1
  • C:\Users\Public\music\info.bat
  • C:\Users\Public\music\up.zip
  • C:\Users\Public\music\res.log
  • C:\Users\Public\music\mustd.exe

Services

  • Network Monitor Serial Service
  • OneDrive client application
  • Ntmssvc
  • Svcsvc

Network indicators

IP Country Organization
123.58.203.41 India AS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED
154.89.152.59 Malaysia AS139923 ABCCLOUD SDN.BHD.
31.57.35.21 United Kingdom AS21859 Zenlayer Inc
5.39.253.206 Kazakhstan AS49791 Newserverlife LLC

We are monitoring the development of events and will update the material on the website as new details emerge.

#dfir #ir #ti
@ptescalator

More from oUth0R

More from oUth0R

More in General