A Belarusian hacktivist gang allegedly maintained access to the network of a Russian healthcare organization for almost two years, potentially gaining access to sensitive medical information, cybersecurity researchers have reported.
Researchers from Russian cybersecurity company Solar said they discovered the intrusion in December 2025. However, their investigation found evidence suggesting that the attackers had entered parts of the organization’s infrastructure as early as 2024.
Attack details
The attack was attributed to the Belarusian Cyber Partisans, a group known for cyber operations against Belarusian and Russian government organizations and businesses.
Despite remaining inside the network for an extended period, the attackers did not appear to destroy systems or cause major disruption. Researchers believe maintaining access may have been more valuable to the attackers than immediately carrying out destructive activity.
Intrusion details
Solar researchers identified several tools associated with the intrusion, including an updated version of the Vasilek Windows backdoor.
Vasilek was previously documented by Kaspersky as malware used by the Cyber Partisans. The backdoor can communicate with attackers through the Telegram Bot API and receive commands through a Telegram group. It can collect information from infected computers, execute Windows commands, transfer files, capture screenshots and record keystrokes.
Attack tactic
Solar said the newer version found during its investigation was version 1.5.8. Researchers also identified techniques for maintaining persistence inside the victim’s environment. These included Windows services and the replacement of the vmtools.dll library associated with VMware Tools.
The attackers also used other communication and tunnelling tools, including DNS tunnels and proxy chains. This gave them alternative methods of communicating with compromised systems if one channel became unavailable.
Telegram restrictions in Russia affected Vasilek’s communications, but researchers said the attackers could use other methods to maintain their access.
What next?
The compromised organization was not publicly identified. However, researchers said it operated a large infrastructure connected to multiple other healthcare organizations.
This created a potential trusted-relationship attack risk. Once attackers gained control of one organization, its connections with other trusted healthcare entities could potentially provide opportunities to reach additional networks.
The researchers said the attackers accessed sensitive medical data but did not destroy the victim’s systems. The long period of access suggests that espionage, intelligence gathering and maintaining future access may have been more important than immediate disruption.
