Cyber Partisans lurked 2 years in Russian health network
A Belarusian hacktivist group appears to have kept quiet access to the network of a Russian healthcare organization for almost two years, possibly reaching sensitive medical data, according to Russian security researchers.
The findings come from Solar, a Russian cybersecurity company owned by Rostelecom, the state-controlled telecom operator. Solar said it detected the intrusion in December 2025, but the earliest traces of compromise date back to early 2024.
In a report published last week, the researchers blamed the Belarusian Cyber Partisans. The group is mainly known for disruptive operations against government bodies and companies in Belarus and Russia.
A gateway to other targets
Solar did not name the victim. It said the organization runs large infrastructure that connects to many other healthcare organizations. That position could have given the attackers a way to move from the compromised network to further victims.
According to the researchers, the intruders reached sensitive medical data but did not disrupt or destroy any systems during their time inside.
"We believe the lack of destructive activity was linked to the value of maintaining this access for further espionage and trusted-relationship attacks," the researchers said.
A trusted-relationship attack works in two steps. The attacker first breaks into an organization that the real target already trusts. The attacker then abuses that existing connection to reach the target.
Vasilek backdoor talks over Telegram
One of the tools found in the network was Vasilek, a Windows backdoor that receives commands from its operators through Telegram. Kaspersky first described the malware in 2025. Solar said the sample it analyzed was a newer version.
Once on a machine, Vasilek can:
- collect information about the infected computer
- run Windows commands
- start and stop processes
- transfer files
- take screenshots
- log keystrokes
- update or remove itself
Solar noted that Russian restrictions on Telegram have made the link between Vasilek and its command-and-control servers less stable. The researchers added that the operators can move to other communication channels.
The Belarusian Cyber Partisans did not respond to a request for comment on Solar's claims at the time the original report was published.
Who the Cyber Partisans are
The group formed after mass protests against Belarusian President Alexander Lukashenko that followed the disputed 2020 presidential election. Western governments rejected that vote as fraudulent.
Since then, the Cyber Partisans have claimed some of the largest cyberattacks on the Belarusian state, including operations against government institutions and the national railway system.
After the start of the war in Ukraine, the group shifted more of its attention to Russian organizations. Those operations have aimed both at stealing intelligence and at disrupting operations.
In July, Russia's Supreme Court labeled the Cyber Partisans an "extremist organization." The court accused the group of trying to destabilize Russia and Belarus and of seeking to overthrow the Belarusian government through unconstitutional means. This was the first time Russia had used the extremist designation against a hacking group.
The group mocked the decision. "They can't stop us, so they're at least doing something to show they're useful," it said. "And we will keep destabilizing the dictatorship!"
Our Take
The most notable detail in Solar's report is what the attackers did not do. A group known for loud, disruptive operations seems to have chosen patience instead, keeping access open rather than wiping systems. If the attribution is correct, this suggests the Cyber Partisans are working more like an espionage team than a classic hacktivist crew. Readers should treat the attribution with some care, though. It comes from a Rostelecom subsidiary and has not been confirmed by the group.
The case also shows why healthcare networks are attractive. An organization connected to many others becomes a launch point for trusted-relationship attacks, and medical records carry lasting value. Healthcare security is a concern in other countries too, as the healthcare cybersecurity bill moving through the US Congress and recent breaches like Clover Health show.
It is worth watching whether Solar or other researchers identify downstream victims, and whether Vasilek's operators move away from Telegram as Russian restrictions tighten.
