# Belarusian Cyber Partisans maintain two-year undetected access to Russian healthcare network using Vasilek Telegram backdoor

> Russian firm Solar (Rostelecom) reports that the Belarusian Cyber Partisans hacktivist group sat inside an unnamed Russian healthcare organization's network for about two years, from early 2024 until discovery in December 2025. The actors used the Telegram-controlled Vasilek backdoor, DNS tunnelers and GOST proxies, and reached sensitive medical data and connected healthcare organizations; no destructive activity was observed.

- **Published:** 2026-10-05T00:00:00Z
- **Last reviewed:** 2026-10-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2950
- **ID:** TL-2026-2950
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** Cyber Partisans (Belarus)
- **Detections:** 9 · **IOCs:** 35 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Solar (the Rostelecom cybersecurity subsidiary) investigated an intrusion at a Russian healthcare organization with extensive infrastructure and connections to numerous other healthcare entities. Earliest signs of compromise date to early 2024 and the intrusion was discovered in December 2025. Solar attributes the activity to the Belarusian Cyber Partisans. This is a vendor-sourced attribution that has not been independently verified. Solar assesses that the absence of destructive activity was linked to the value of keeping the access for further espionage. The group accessed sensitive medical data and abused trusted relationships to reach connected healthcare organizations.

Execution and lateral movement relied on Impacket wmiexec.py, which runs cmd.exe with output redirected to files under \\127.0.0.1\ADMIN$ (named __<unix timestamp>.<microseconds>). The actors also used legitimate RDP access and SMB command execution over ADMIN$; Microsoft-Windows-SMBServer/Security Event ID 1015 is a relevant log source. Temporary parameter changes to the AppMgmt service were made with StealthyWMIExec/NimExec-style techniques. Persistence used five Windows services (tpvmmon, aweman32, uplay_r164 loading DNSCat2; msadcs32 loading the PartisanDNS DNS tunneler; vmauad, a VMware Authentication Adapter lookalike, loading a custom scheduler-loader authd.exe). The actors also hijacked C:\Program Files\VMware\VMware Tools\vmtools.dll with an unsigned Vasilek backdoor, keeping the original as vmtoolsd.dll so it could be rolled back.

The scheduler-loader authd.exe is configuration driven. It supports an interval trigger (+480 minutes after service start), a cron-style window (Saturday 22:00-23:00 UTC for the GOST proxy) and SHA-256 hostname keying of its task structures, so payloads run only on intended hosts. Scheduled payloads were vmtoolsd32.exe (GOST proxy), rpctool32.exe (Vasilek 1.5.8) and E:\WSUS\UpdateServicesPackages\WsusService.exe (GOST). Vasilek v1.5.8 is a Windows backdoor controlled through the Telegram Bot API, with commands issued through a group (GroupAnonymousBot). It is obfuscated with OLLVM control-flow flattening, repeating-key XOR with per-position bit rotation, and a Vigenère-encoded command table, and it has 59 commands. These cover shell execution, screenshots, keylogging (key_on), window tracking, process and file operations, and self-deletion via cmd /c del. It uses an embedded TLSe/LibTomCrypt TLS stack instead of Schannel, so its JA3/JA4 fingerprint differs from normal Windows applications. Five C2 domains were observed, four of them new single-character-prefix variants of previously known domains (c0ce.org, p7cp.org, w3a01.net, f91j.org, plus gov-by.com). PartisanDNS uses a DGA over many TLDs on the vfvnfaq second-level domain.

Kaspersky's June 2025 report on Cyber Partisans TTPs documented the same toolset in earlier intrusions: Vasilek (Telegram-controlled), DNSCat2, 3proxy, Gost, SeekDNS, and the Pryanik time-triggered wiper (CVE-2021-31728 driver abuse). Solar says the Vasilek version it examined is newer. Russia's Supreme Court designated the group an extremist organization in July 2026. Defenders should note that the group was a destructive actor against Belarusian and Russian targets in other campaigns, so access of this kind carries latent destructive potential even though none was observed here.

## MITRE ATT&CK

- T1199 Trusted Relationship
- T1047 Windows Management Instrumentation
- T1569.002 Service Execution
- T1059.003 Windows Command Shell
- T1543.003 Windows Service
- T1574.001 DLL
- T1480.001 Environmental Keying
- T1036.005 Match Legitimate Resource Name or Location
- T1070.006 Timestomp
- T1082 System Information Discovery
- T1021.001 Remote Desktop Protocol
- T1021.002 SMB/Windows Admin Shares
- T1113 Screen Capture
- T1056.001 Keylogging
- T1102.002 Bidirectional Communication
- T1071.004 DNS
- T1572 Protocol Tunneling
- T1090 Proxy

## Sources

- [Belarusian hacktivists spent two years inside Russian healthcare network, researchers say](https://therecord.media/belarusian-hacktivists-two-years-Russian-healthcare-network)
- [Solar 4RAYS: attack on a medical organization (Partisan Zmiy)](https://rt-solar.ru/solar-4rays/blog/7027/)
- [Kaspersky ICS CERT: TTPs of Cyber Partisans activity aimed at espionage and disruption](https://ics-cert.kaspersky.com/publications/reports/2025/06/05/ttps-of-cyber-partisans-activity-aimed-at-espionage-and-disruption/)
- [Belarusian hackers taunt Kaspersky over report detailing their attacks](https://www.therecord.media/belarusian-hackers-taunt-kaspersky-ver-report)
- [Belarusian hacktivists unfazed by Kaspersky's report](https://www.scworld.com/brief/belarusian-hacktivists-unfazed-by-kasperskys-report)
- [Russian malware discovered with Telegram hacks for C2 operations](https://www.csoonline.com/article/3826808/russian-malware-discovered-with-telegram-hacks-for-c2-operations.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2950
