Vasilek Backdoor Gave Hackers Prolonged Access to a Russian Healthcare Network
Solar links Belarusian Cyber Partisans to a 2024-2025 intrusion in Russian healthcare using Vasilek Telegram backdoor to access medical data.
Illustrative image generated with AI
Russian cybersecurity company Solar has attributed a prolonged intrusion at an unnamed healthcare organization to the Belarusian Cyber Partisans, saying the attackers accessed sensitive medical information without disrupting the victim’s systems.
Solar, a subsidiary of state-controlled telecommunications provider Rostelecom, discovered the compromise in December 2025. Its researchers traced the earliest evidence of intrusion to early 2024, indicating that the attackers may have remained inside the environment for an extended period before detection.
The company disclosed its findings in a report released last week, although an exact publication date was not provided in the account of the investigation.
Solar’s timeline, malware analysis and attribution have not been independently verified in the available material. The Belarusian Cyber Partisans did not respond to a request for comment from the publication reporting the findings.
A healthcare target connected to other organizations
The victim was described as a Russian healthcare organization operating substantial infrastructure linked to numerous other entities in the same sector. Solar did not publicly identify it.
Those relationships potentially increased the value of the intrusion. An attacker controlling systems inside a trusted organization could attempt to exploit existing connections, credentials or communications to approach additional targets.
Solar characterized this possibility as a risk from trusted-relationship attacks. However, the available reporting does not establish that the intruders successfully used the healthcare organization to compromise any connected entity.
Researchers said the attackers obtained access to sensitive medical data. The available information does not quantify the number of patients, records, systems or organizations affected, and access should not automatically be interpreted as confirmed data theft. No evidence provided in the reporting establishes whether the medical information was exfiltrated.
Solar also reported that the attackers neither destroyed systems nor interrupted the organization’s operations. That distinguishes the incident, as described, from ransomware and destructive attacks that immediately impair patient care or administrative services.
The absence of disruption does not make the compromise harmless. Medical environments hold personal, clinical and operational information that can retain intelligence value long after an attacker obtains it.
Vasilek provided remote control through Telegram
The attackers reportedly deployed Vasilek, a Windows backdoor that communicates with its operators through Telegram. Kaspersky first documented the malware in 2025, while Solar said the sample found during this investigation represented a newer iteration. No exact Vasilek version number was disclosed in the supplied reporting.
According to Solar’s analysis, Vasilek can collect information about an infected Windows computer and execute commands remotely. Its capabilities also include:
- Starting and terminating processes.
- Uploading or downloading files.
- Capturing screenshots.
- Recording keystrokes.
- Updating itself.
- Removing itself from an infected host.
Together, these functions would allow an operator to inspect a compromised device, collect credentials or other typed information, observe user activity and deploy additional files. The self-update capability also gives operators a way to alter the malware after infection, while self-deletion can help remove the implant when access is no longer required.
Telegram serves as the communications channel between Vasilek and its operators. Solar said restrictions affecting Telegram in Russia reduced the reliability of those command-and-control connections.
That disruption should not be treated as a complete defensive measure. The researchers said the attackers could move to other communications methods, meaning that blocking or degrading Telegram alone would not necessarily remove an existing infection or prevent the operators from regaining control.
The reporting provides no CVE identifiers, named software vulnerabilities or affected product versions. It therefore does not indicate that a specific patchable flaw was the initial entry point.
Solar interprets restraint as an espionage choice
Solar assessed that the attackers may have deliberately preserved the victim’s systems rather than damaging them. In the researchers’ interpretation, maintaining quiet access supported intelligence collection and left open the possibility of reaching other organizations through trusted relationships.
That is an analytical judgment, not a confirmed statement of the attackers’ intent. Several facts support the possibility of an intelligence-oriented operation—the long apparent dwell time, access to medical data and lack of destructive activity—but they do not independently prove why the operators acted as they did.
The distinction matters because the Belarusian Cyber Partisans have previously claimed both intelligence-gathering and disruptive operations. A group’s historical activity does not establish the objective of every intrusion attributed to it.
Solar attributed this operation to the group, but the available account does not include the underlying forensic evidence supporting that conclusion. It also does not describe infrastructure overlaps, code similarities, operator mistakes or other technical links that could allow outside researchers to evaluate the attribution.
For now, the identity of the operator remains Solar’s assessment rather than an independently confirmed fact.
What healthcare defenders can act on
The available reporting does not include hashes, domains, IP addresses, file paths or other indicators that could support a precise Vasilek hunt. It also does not provide a vendor-specific remediation procedure. That limitation applies to the material describing the incident and does not establish that Solar has published no additional information elsewhere.
Healthcare security teams can still use the reported behavior to guide broader investigation. Relevant areas include unexpected Telegram-related connections from Windows endpoints, unexplained command execution, unusual process creation or termination, suspicious file transfers, and evidence of screenshot or keystroke-capture activity.
These signals are not unique to Vasilek. Any alert should therefore be correlated with endpoint telemetry, network logs and user activity before being treated as evidence of this malware.
Organizations with extensive links to hospitals, clinics, laboratories or service providers should also review how those connections are authenticated and segmented. A compromised trusted partner can provide attackers with a more convincing identity or a route into systems that would otherwise be inaccessible.
Where compromise is suspected, restricting Telegram traffic may interrupt the reported command channel, but it should not replace endpoint containment, credential review and examination for alternative communications. Solar explicitly assessed that the operators could change methods.
Attribution carries a broader political context
The Belarusian Cyber Partisans emerged after mass protests against President Alexander Lukashenko following Belarus’s disputed 2020 presidential election. Western governments rejected that election as fraudulent.
The group has claimed responsibility for attacks against Belarusian state institutions and the national railway system. Since the beginning of the war in Ukraine, it has increasingly focused on Russian organizations in operations described as pursuing intelligence collection or disruption.
Russia’s Supreme Court designated the Belarusian Cyber Partisans an “extremist organization” in July. The year of that decision was not specified in the available material. The court accused the group of trying to destabilize Russia and Belarus and overthrow the Belarusian government through unconstitutional means.
According to the reporting, this was the first time Russia had applied that designation to a hacking group. The Cyber Partisans rejected the ruling and said they would continue efforts against the Belarusian dictatorship.
That political history provides context for Solar’s attribution, but it does not independently verify the healthcare intrusion. The confirmed scope remains narrower: Solar found the compromise in December 2025, traced activity back to early 2024, identified Vasilek in the environment and reported access to sensitive medical information. Further compromise through the victim’s healthcare connections remains a reported risk, not an established outcome.
Sources
This article is an original reworking based on the sources below.




