Threat reportAPTTL-2026-2950
Belarusian Cyber Partisans maintain two-year undetected access to Russian healthcare network using Vasilek Telegram backdoor
Belarusian Cyber Partisans maintain two-year undetected (TL-2026-2950) is a high-severity advanced persistent threat campaign, first published 2026-10-05. It is attributed to Cyber Partisans (Belarus) with medium confidence, affects Unnamed Russian healthcare organization Windows servers and, maps to 18 MITRE ATT&CK techniques (T1021.001, T1021.002, T1036.005), and is covered by 9 detection rules and 35 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 18MITRE ATT&CK
- Actors
- 1Cyber Partisans
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 35Indicators of compromise
Key facts for TL-2026-2950
- Threat ID
- TL-2026-2950
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- Cyber Partisans
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Belarus
- Motivation
- ESPIONAGE
- Target sectors
- health
- Target regions
- russia
- Detection rules
- 9
- Indicators of compromise
- 35
Malware and tooling in Belarusian Cyber Partisans maintain two-year undetected
Malware and tooling: PartisanDNS, Vasilek, DNSCat2, GOST, Impacket - S0357, Impacket wmiexec, Wmiexec
How Belarusian Cyber Partisans maintain two-year undetected works
Russian firm Solar (Rostelecom) reports that the Belarusian Cyber Partisans hacktivist group sat inside an unnamed Russian healthcare organization's network for about two years, from early 2024 until discovery in December 2025. The actors used the Telegram-controlled Vasilek backdoor, DNS tunnelers and GOST proxies, and reached sensitive medical data and connected healthcare organizations; no destructive activity was observed.
Solar (the Rostelecom cybersecurity subsidiary) investigated an intrusion at a Russian healthcare organization with extensive infrastructure and connections to numerous other healthcare entities. Earliest signs of compromise date to early 2024 and the intrusion was discovered in December 2025. Solar attributes the activity to the Belarusian Cyber Partisans. This is a vendor-sourced attribution that has not been independently verified. Solar assesses that the absence of destructive activity was linked to the value of keeping the access for further espionage. The group accessed sensitive medical data and abused trusted relationships to reach connected healthcare organizations.
Execution and lateral movement relied on Impacket wmiexec.py, which runs cmd.exe with output redirected to files under \\127.0.0.1\ADMIN$ (named __<unix timestamp>.<microseconds>). The actors also used legitimate RDP access and SMB command execution over ADMIN$; Microsoft-Windows-SMBServer/Security Event ID 1015 is a relevant log source. Temporary parameter changes to the AppMgmt service were made with StealthyWMIExec/NimExec-style techniques. Persistence used five Windows services (tpvmmon, aweman32, uplay_r164 loading DNSCat2; msadcs32 loading the PartisanDNS DNS tunneler; vmauad, a VMware Authentication Adapter lookalike, loading a custom scheduler-loader authd.exe). The actors also hijacked C:\Program Files\VMware\VMware Tools\vmtools.dll with an unsigned Vasilek backdoor, keeping the original as vmtoolsd.dll so it could be rolled back.
The scheduler-loader authd.exe is configuration driven. It supports an interval trigger (+480 minutes after service start), a cron-style window (Saturday 22:00-23:00 UTC for the GOST proxy) and SHA-256 hostname keying of its task structures, so payloads run only on intended hosts. Scheduled payloads were vmtoolsd32.exe (GOST proxy), rpctool32.exe (Vasilek 1.5.8) and E:\WSUS\UpdateServicesPackages\WsusService.exe (GOST). Vasilek v1.5.8 is a Windows backdoor controlled through the Telegram Bot API, with commands issued through a group (GroupAnonymousBot). It is obfuscated with OLLVM control-flow flattening, repeating-key XOR with per-position bit rotation, and a Vigenère-encoded command table, and it has 59 commands. These cover shell execution, screenshots, keylogging (key_on), window tracking, process and file operations, and self-deletion via cmd /c del. It uses an embedded TLSe/LibTomCrypt TLS stack instead of Schannel, so its JA3/JA4 fingerprint differs from normal Windows applications. Five C2 domains were observed, four of them new single-character-prefix variants of previously known domains (c0ce.org, p7cp.org, w3a01.net, f91j.org, plus gov-by.com). PartisanDNS uses a DGA over many TLDs on the vfvnfaq second-level domain.
Kaspersky's June 2025 report on Cyber Partisans TTPs documented the same toolset in earlier intrusions: Vasilek (Telegram-controlled), DNSCat2, 3proxy, Gost, SeekDNS, and the Pryanik time-triggered wiper (CVE-2021-31728 driver abuse). Solar says the Vasilek version it examined is newer. Russia's Supreme Court designated the group an extremist organization in July 2026. Defenders should note that the group was a destructive actor against Belarusian and Russian targets in other campaigns, so access of this kind carries latent destructive potential even though none was observed here.
MITRE ATT&CK techniques used in TL-2026-2950
Lateral Movement
T1021.001 Remote Desktop Protocol; T1021.002 SMB/Windows Admin Shares
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location; T1070.006 Timestomp; T1480.001 Environmental Keying
Execution
T1047 Windows Management Instrumentation; T1059.003 Windows Command Shell; T1569.002 Service Execution
Collection
T1056.001 Keylogging; T1113 Screen Capture
Command and Control
T1071.004 DNS; T1090 Proxy; T1102.002 Bidirectional Communication; T1572 Protocol Tunneling
Discovery
T1082 System Information Discovery
Initial Access
Persistence
stealth
Affected products and versions in Belarusian Cyber Partisans maintain two-year undetected
- Unnamed Russian healthcare organization — Windows servers and workstations (VMware Tools, WSUS hosts)
Remediation for Belarusian Cyber Partisans maintain two-year undetected
Immediate actions
- Hunt for the Windows services tpvmmon, aweman32, msadcs32, uplay_r164 and vmauad and for the paths and hashes in the IOC list
- Check C:\Program Files\VMware\VMware Tools\ for an unsigned vmtools.dll alongside a renamed vmtoolsd.dll, and for authd.exe, vmtoolsd32.exe and rpctool32.exe
- Block and sinkhole the listed C2 and DNS-tunnel domains; alert on DNS queries to vfvnfaq.* and on DNS TXT/NULL tunneling patterns
- Review outbound access to the Telegram Bot API (api.telegram.org) from servers and non-user hosts
Workarounds
- Block egress to Telegram from server segments that have no business need for it
- Enforce application allow-listing so unsigned binaries cannot run from VMware Tools or WSUS directories
Longer-term hardening
- Alert on ADMIN$ writes of files named __<unix timestamp>.<microseconds> (Impacket wmiexec) and on SMBServer/Security Event ID 1015
- Monitor for unusual JA3/JA4 fingerprints from VMware Tools or WSUS directories
- Restrict and audit trust relationships, VPNs and remote access between healthcare partner organizations
- Restrict creation of new services and DLL replacement in VMware Tools and WSUS directories
Timeline of Belarusian Cyber Partisans maintain two-year undetected
- Earliest signs of compromise at the Russian healthcare organization (early 2024; exact day not given). Impacket wmiexec activity is among the earliest traces.
- Kaspersky ICS CERT publishes its report on Cyber Partisans TTPs, first documenting Vasilek, DNSCat2, Gost, 3proxy and the Pryanik wiper.
- Solar discovers the intrusion during an investigation (December 2025; exact day not given), after roughly two years of dwell time.
- Russia's Supreme Court designates the Cyber Partisans an extremist organization (July 2026; exact day not given).
- Solar publishes its technical report on the attack in the Solar 4RAYS blog.
- The Record publishes coverage of the Solar report; the Cyber Partisans respond dismissively.
Sources cited for Belarusian Cyber Partisans maintain two-year undetected
- Belarusian hacktivists spent two years inside Russian healthcare network, researchers say
- Solar 4RAYS: attack on a medical organization (Partisan Zmiy)
- Kaspersky ICS CERT: TTPs of Cyber Partisans activity aimed at espionage and disruption
- Belarusian hackers taunt Kaspersky over report detailing their attacks
- Belarusian hacktivists unfazed by Kaspersky's report
- Russian malware discovered with Telegram hacks for C2 operations
Detection coverage for TL-2026-2950
As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2950 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.