Solar researchers attributed a nearly two-year intrusion into an unnamed Russian healthcare organization to the Belarusian Cyber Partisans. Investigators discovered the compromise in December 2025 and traced the earliest evidence of access to early 2024. The attackers reportedly accessed sensitive medical information without apparent system disruption or destruction. Solar assessed that intelligence gathering and preserving access may have taken priority over immediate sabotage. The victim’s connections to numerous other healthcare organizations created potential opportunities for trusted-relationship attacks, but the reporting did not confirm any downstream compromises.
The operation used Vasilek, a Windows backdoor that communicates through Telegram and supports command execution, file transfers, screenshots, and keylogging. Additional reporting identified version 1.5.8, persistence through Windows services and replacement of a VMware Tools library, and alternative communications using DNS tunnels and proxy chains. Healthcare defenders should review service creation, validate VMware Tools library integrity, investigate unexpected Telegram traffic and DNS tunneling, and assess access granted through interorganizational connections. The attribution and espionage assessment remain researchers’ conclusions; one secondary account also carried a mismatched original-source link, limiting its independent corroboration.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
Russia's Supreme Court designated the Belarusian Cyber Partisans an extremist organization, accusing the group of seeking to destabilize Russia and Belarus. The ruling was reportedly Russia's first extremist designation of a hacking group.
Solar discovered the intrusion in December 2025 and found evidence that attackers had maintained access for nearly two years. Researchers reported access to sensitive medical data without apparent major disruption or destruction of the victim's systems.
Kaspersky first documented Vasilek, a Windows backdoor used by the Belarusian Cyber Partisans. The malware communicates through Telegram and supports command execution, file transfers, screenshots, and keylogging.
Evidence later examined by Solar traced the compromise of an unidentified Russian healthcare organization to early 2024. The organization operated extensive infrastructure connected to numerous other healthcare organizations.
The Belarusian Cyber Partisans claimed they breached the Moscow Department of Health in 2023 and obtained administrator-level access to infrastructure connected to other government agencies. The group said it abandoned the operation after months, contradicting Solar's assessment that access may have persisted for nearly two years.
Solar attributed the intrusion to the Belarusian Cyber Partisans and reported an updated Vasilek backdoor, identified as version 1.5.8. Reported techniques included persistence through Windows services and replacement of VMware Tools' vmtools.dll, alongside DNS tunnels and proxy chains for alternative communications.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
4 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcecysecurity.news
Open sourcetherecord.media
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.