Vasilek is a Windows backdoor associated with the Belarusian hacktivist group Cyber Partisans and first documented by Kaspersky in 2025. It uses Telegram for command-and-control communications and data exfiltration, including the Telegram Bot API to exchange information with operators and receive commands through a Telegram group.
Vasilek supports collecting information about infected computers, executing Windows commands, launching and terminating processes, transferring files, capturing screenshots, and recording keystrokes. It can also update or delete itself. These capabilities enable remote control, surveillance, and information theft. Vasilek has been used against industrial enterprises and government agencies in Russia and Belarus, and an updated version was identified in a prolonged intrusion into a Russian healthcare organization attributed to Cyber Partisans.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Solar researchers identified several tools associated with the intrusion, including an updated version of the Vasilek Windows backdoor. Vasilek was previously documented by Kaspersky as malware used by the Cyber Partisans.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows backdoor used by the Belarusian Cyber Partisans in a prolonged intrusion into a Russian healthcare organization. It communicates through the Telegram Bot API and receives commands through a Telegram group. Its capabilities include collecting system information, executing Windows commands, transferring files, capturing screenshots and recording keystrokes. Researchers identified version 1.5.8 during the investigation. Telegram restrictions in Russia affected its communications, although the attackers had alternative communication channels.
Windows backdoor used in the Belarusian Cyber Partisans' prolonged intrusion into a Russian healthcare organization. It collects system information, executes Windows commands, launches and terminates processes, transfers files, captures screenshots, records keystrokes, and can update or delete itself. It uses Telegram for command-and-control communications, which Solar reported had become less reliable because of restrictions in Russia. The examined version was newer than the version first documented by Kaspersky in 2025.
Windows backdoor reportedly used by the Belarusian Cyber Partisans in a prolonged espionage operation against an unidentified Russian healthcare organization. It communicates through Telegram and supports system-information collection, Windows command execution, process management, file transfers, screenshots, keylogging, updating, and self-deletion. The content reports use of a newer version and alternative communication methods, but provides no technical details about those alternatives. The supplied source URL does not match the described article, so these claims are not independently verified.
Backdoor used for remote access and data exfiltration, leveraging Telegram for command and control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.