Skip to main content
LiMP VPN
All news

ViPNet Client Flaw: Hackers Delivered Malware via Updates

ViPNet Client Flaw: Hackers Delivered Malware via Updates

In short: Positive Technologies has disclosed a critical vulnerability, PT-2026-19 (CVSS 9.0), in ViPNet Client — a corporate VPN suite protecting more than 10 million workstations across Russia. Between June and July 2026, attackers exploited the flaw via the software's trusted auto-update channel, compromising at least 8 organisations. Patches are available; updating is mandatory.

What Happened: An Attack Through a Trusted Update Channel

In August 2026, the Positive Technologies Expert Security Center (PT ESC) published findings from an investigation into targeted attacks on Russian corporate networks. The attack vector was ViPNet Client — a VPN software suite by InfoTeCS, widely used across Russian government bodies, banks, industrial enterprises, and healthcare institutions. For context on how corporate and consumer VPN security differ, see our data security blog.

The vulnerability is tracked as PT-2026-19 (BDU:2026-09885) and carries a CVSS score of 9.0. According to researchers, active exploitation was recorded between 1 June and 14 July 2026 and affected at least 8 Russian organisations.

Attack Technique: DLL Hijacking via the MFTP Protocol

ViPNet uses a proprietary MFTP transport protocol to exchange files between network nodes, including delivering software updates. To execute the attack, adversaries first had to gain control of a node running ViPNet Administrator — meaning they needed privileged access inside the corporate VPN network.

The attack chain combined two techniques. Attackers crafted a malicious mail-envelope file (.ctl) embedding a weaponised wtsapi32.dll library. This file was delivered to target hosts via MFTP and loaded by Itcsrvup64.exe — the ViPNet update service component. The exploitation combined DLL Hijacking (substituting a system library within a trusted process) and Path Traversal (escaping the permitted directory to write the payload). The result: arbitrary code execution with elevated privileges on every host that received the poisoned update.

What makes this vulnerability especially dangerous is that it operated through a legitimate, trusted channel — the very mechanism organisations rely on without additional scrutiny. The attackers worked undetected for six weeks before discovery.

Scale of Exposure: 10 Million Workstations

ViPNet is one of Russia's most widely deployed corporate VPN platforms. According to the developer (InfoTeCS), the product protects more than 10 million workstations across thousands of organisations. This meant a single compromised Administrator node could propagate malicious code across all subordinate workstations in the network — an enormous potential blast radius.

Positive Technologies has not disclosed the identities of affected organisations but confirmed these were real-world production incidents. Attacks of this type — where malware spreads through a trusted security tool — fall into the software supply chain attack category, one of the most dangerous vectors of 2026. For more on active threats targeting Russian users, see our piece on Android banking trojans targeting Russia.

How to Protect Your Organisation: Update Now

InfoTeCS has released patches addressing PT-2026-19. The vulnerability is fixed in the following versions of ViPNet Client 4:

  • 4.5.3-65211 or later
  • 4.5.5.24749 or later

Organisations using ViPNet Client should:

  1. Immediately update ViPNet Client to a patched version on all hosts.
  2. Review event logs for indicators of compromise covering June–August 2026.
  3. Apply least-privilege principles to ViPNet Administrator node access.
  4. Ensure antivirus software does not exclude ViPNet directories from scanning.

What This Means for Your Data

Successful exploitation gave attackers full control of the compromised workstation — access to corporate communications, documents, credentials, and encryption keys. The incident demonstrates that even a dedicated security tool can become an attack vector if its update pipeline lacks integrity verification.

For individual users concerned about personal privacy, the takeaway is to choose VPN services with transparent policies and independent audits — a trustworthy provider publishes its security practices openly. LiMP VPN is a no-logs service for iOS and Android with an open privacy policy.

Sources

Positive Technologies on Habr: August Trending VM Digest — ViPNet Client, Microsoft Windows kernel, and SharePoint · SecurityLab: Three nines out of ten — PT named four August vulnerabilities already exploited in attacks · PT ESC: Attack via ViPNet MFTP — signs of compromise and recommendations

ViPNet Client Flaw: Hackers Delivered Malware via Updates