APTMedium

Belarusian hacktivists spent nearly two years inside a Russian healthcare network

Researchers at Rostelecom subsidiary Solar say the Belarusian Cyber Partisans held access to a Russian healthcare organisation from early 2024 until December 2025, using a Telegram-controlled backdoor and taking no destructive action.

Belarusian hacktivists spent nearly two years inside a Russian healthcare network

At a glance

  • Solar, a cybersecurity subsidiary of Russian state-controlled Rostelecom, attributes the intrusion to the Belarusian Cyber Partisans
  • The group held access from early 2024 until discovery in December 2025 and reached sensitive medical information
  • The toolkit centred on a Windows backdoor called Vasilek that takes commands over Telegram
  • Researchers saw no destructive activity, linking that restraint to the value of keeping the access alive

A hacktivist group operating against the Belarusian and Russian governments kept access to a Russian healthcare organisation's network for nearly two years without being detected, according to research reported by The Record on October 5, 2026. The findings were published by Solar, a cybersecurity subsidiary of the Russian state-controlled telecommunications firm Rostelecom, which attributes the intrusion to the Belarusian Cyber Partisans.

What happened

The Record reports that the intrusion began in early 2024 and was only discovered in December 2025. The targeted organisation is not named, but according to the report it operates extensive infrastructure that connects to numerous other healthcare entities — meaning the foothold carried reach well beyond a single hospital network.

Solar's researchers found that the attackers accessed sensitive medical information, though The Record notes the specifics of what was taken were not disclosed. Notably, the report describes no destructive activity at all: no wiping, no leak-site posting, no disruption of clinical systems. Researchers linked that restraint directly to the value of maintaining the access, indicating the operation was run for intelligence collection rather than for public impact.

Technical details

According to The Record, the campaign centred on a Windows backdoor the researchers call Vasilek, which communicates with its operators over Telegram — a channel that blends into ordinary traffic and avoids the dedicated command-and-control infrastructure defenders tend to watch for.

The backdoor's reported capabilities cover the standard espionage toolkit: collecting information about infected systems, executing commands, managing processes, transferring files, capturing screenshots and logging keystrokes. It can also update itself and delete itself, which helps an operator stay current and remove traces when an endpoint becomes risky.

Who is affected

The directly affected party is the unnamed Russian healthcare organisation and, potentially, the other healthcare entities reachable through its infrastructure. The wider lesson is about dwell time rather than geography: a hacktivist group with modest, Telegram-based tooling went unnoticed on a healthcare network for roughly 22 months, and it was an external research effort rather than internal monitoring that appears to have surfaced it.

The Record also notes the political backdrop. The Cyber Partisans — who have previously claimed attacks on Belarusian state systems — responded to Russia designating them as extremist by saying: "They can't stop us, so they're at least doing something to show they're useful."

What to do

Because no vulnerability or patch is at the centre of this case, the defensive takeaways are detection-oriented. Health sector security teams should treat outbound connections to consumer messaging platforms, including the Telegram API, as something to inventory and alert on from server and clinical workstation segments where such traffic has no business reason. Hunting for long-lived keylogging and screenshot activity, reviewing how far trust extends from shared infrastructure to partner organisations, and periodically assuming a quiet intruder is already present are more useful here than any single indicator. The absence of damage is not evidence of absence of access.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.