Hackers Sat Quietly Inside a Russian Healthcare Network for Nearly Two Years
A Belarusian activist hacking group reportedly spent nearly two years inside the network of a Russian healthcare organisation, potentially gaining access to sensitive medical data. Russian cybersecurity firm Solar, a subsidiary of Rostelecom, said it discovered the intrusion in December 2025 but traced the earliest signs of compromise to early 2024. Its report attributes the attack to the Belarusian Cyber Partisans, a group best known for disruptive attacks on government agencies and businesses in Belarus and Russia. The victim was not named, and the group did not respond to a request for comment.
The hackers accessed medical data but did not disrupt or destroy any systems. Solar believes this restraint was deliberate, because keeping access was more valuable for further espionage and for trusted-relationship attacks. In that kind of attack, criminals first compromise an organisation that others already trust, then use that connection to reach their real target. Solar noted the victim ran extensive infrastructure linked to many other healthcare organisations, which could have given the hackers a path to additional targets.
Among the tools used was Vasilek, a Windows backdoor that talks to its operators through Telegram. It can collect information about an infected computer, run commands, start and stop processes, transfer files, capture screenshots and record keystrokes. It can also update or delete itself. Solar said Telegram restrictions in Russia made the malware's communications less reliable, but the hackers could switch to other methods.