NEWS

Belarusian Cyber Partisans Admit to 2023 Breach of Russian Healthcare Network

The hacktivist group confirmed a Russian researcher's report that it held admin-level access inside Moscow's Department of Health network for months in 2023.

Dylan H.

News Desk

October 10, 2026
7 min read
Belarusian Cyber Partisans Admit to 2023 Breach of Russian Healthcare Network

Belarusian Hacktivists Confirm Years-Long Foothold in Russian Health Network

The Belarusian Cyber Partisans, a hacktivist collective formed in the wake of the 2020 protests against President Alexander Lukashenko, have publicly confirmed that they breached the network of the Moscow Department of Health in 2023, obtaining administrator-level access to infrastructure connected to other Russian government agencies and healthcare institutions. The group's admission, given to Recorded Future News (publisher of The Record), corroborates a separate report from Solar, the cybersecurity subsidiary of state-controlled telecom operator Rostelecom, which independently uncovered the intrusion and said forensic evidence showed the attackers' presence in the network for close to two years before it was identified.


Incident Details

AttributeValue
Threat actorBelarusian Cyber Partisans (hacktivist collective)
TargetMoscow Department of Health (Russian state healthcare network)
Claimed initial access2023, per the Cyber Partisans
Discovered bySolar (Rostelecom's cybersecurity subsidiary)
Researchers' earliest observed evidenceEarly 2024
Access level achievedAdministrator-level, across infrastructure linked to other government and healthcare systems
Backdoor identifiedVasilek (Windows malware, Telegram-based command-and-control)
Data impactAccessed sensitive medical records; no reported destruction or operational disruption
Stated motiveAssessing Russian military casualties from the war in Ukraine
Legal status in RussiaGroup designated an "extremist organization" by Russia's Supreme Court, July 2026

How It Happened

Who Are the Cyber Partisans

The Cyber Partisans emerged from the mass protest movement that followed Belarus's disputed 2020 presidential election, initially focused on disrupting Lukashenko-aligned government and security-service systems inside Belarus — including a previously reported intrusion against the Belarusian KGB and attacks on the national railway network timed to Russian troop movements. After Russia's full-scale invasion of Ukraine in 2022, the group expanded its targeting to Russian government and infrastructure networks, framing its operations as both anti-Lukashenko and anti-Kremlin activism. In July 2026, Russia's Supreme Court designated the Cyber Partisans an "extremist organization" — the first time Russia has applied that designation to a hacking group — to which the collective responded by saying it would continue operations against both governments.

The 2023 Intrusion

According to the group's own account, breaking into the Moscow Department of Health's network required little effort. The Cyber Partisans told Recorded Future News that the target "was not a priority" for them, which is why they did not retain persistent access, adding: "We gained full access to its entire infrastructure relatively quickly and with little effort." That access reportedly reached administrator-level privileges across an IT environment that extended beyond the health department itself, touching systems tied to other government agencies and additional healthcare organizations connected to the same network.

How Researchers Found It

Solar, operating as Rostelecom's security arm, identified the intrusion independently and published a report attributing the activity to the Cyber Partisans. Solar's investigators traced the earliest forensic signs of compromise to early 2024 — roughly a year after the date the hacktivists themselves cite for initial access — and assessed that the attackers had maintained a presence in the network for close to two years before detection. Researchers noted the intruders accessed sensitive medical information but did not destroy data or disrupt the health department's operations, a restraint Solar interpreted as consistent with an intelligence-gathering posture rather than disruptive hacktivism — maintaining the foothold "for further espionage and trusted-relationship attacks" against connected organizations.

The Vasilek Backdoor

Among the tools Solar recovered from the compromised environment was Vasilek, a Windows backdoor that uses Telegram for command-and-control communication. The malware was first documented by Kaspersky in 2025, but the sample found in the health department's network was a newer variant. Once deployed, Vasilek can collect host and system information, execute arbitrary Windows commands, launch and terminate processes, transfer files, capture screenshots, and log keystrokes, and it can update or delete itself to cover its tracks. Solar noted that Russia's restrictions on Telegram access have made the malware's C2 channel less reliable at times, though operators retain the ability to switch to alternative communication methods. Investigators also identified persistence mechanisms consistent with a methodical, long-term intrusion: registration of malicious Windows services, and replacement of vmtools.dll, a legitimate library associated with VMware Tools, to blend malicious code into trusted virtualization software on affected hosts.

A Timeline Gap Worth Noting

The Cyber Partisans' claim of 2023 access and Solar's forensic dating to early 2024 do not fully align. The discrepancy could reflect gaps in available log retention, an initial access stage that left little forensic trace before the tooling now attributed to the intrusion was deployed, or simply differing definitions of when "access" began versus when the specific artifacts Solar analyzed were first planted. Either reading still points to a multi-year, largely undetected presence inside a state healthcare network.

Impact Assessment

Impact AreaDescription
ConfidentialitySensitive medical records and healthcare-network data were accessed and potentially exfiltrated
Scope of exposureAccess extended to systems connected to other Russian government agencies and healthcare institutions, beyond the Moscow Department of Health itself
Availability/IntegrityNo reported data destruction or service disruption — consistent with a long-term espionage posture
Attribution confidenceHigh — corroborated independently by both the attacker (Cyber Partisans) and the defender-side researcher (Solar)
Strategic riskDemonstrates that Russian state healthcare infrastructure, often treated as a lower-priority target, can provide administrator-level pivot points into interconnected government networks
Detection latencyUp to roughly two years between initial compromise and discovery, highlighting weak long-term threat hunting in the targeted environment

Recommendations

For Healthcare and Government Network Administrators

  • Segment healthcare IT environments from broader government networks; treat shared infrastructure between a health department and other agencies as a high-value pivot path requiring its own monitoring boundary.
  • Audit vmtools.dll and other VMware Tools components against known-good hashes across virtualized hosts — DLL replacement in trusted virtualization software is a persistence technique that evades casual review.
  • Inventory and monitor for unauthorized Windows services, a common low-effort persistence mechanism that can go unnoticed for years without routine service-baseline audits.

For Security Teams

  • Add detection logic for Telegram-based C2 traffic, including Telegram Bot API calls originating from server or workstation assets that have no legitimate business reason to use the service.
  • Hunt for Vasilek-associated indicators (Kaspersky's 2025 writeup and Solar's newer analysis) across EDR telemetry, particularly process trees showing screenshot capture, keylogging hooks, or arbitrary command execution from unexpected parent processes.
  • Extend log retention windows for critical infrastructure. A detection gap of up to two years, as seen here, is only closeable with retained historical telemetry, not just real-time alerting.

For Organizations Operating Interconnected Networks

  • Reassess trust relationships between departments and affiliated organizations sharing infrastructure; administrator-level compromise of one connected entity can expose all of them.
  • Treat hacktivist groups with sustained operational capability and geopolitical motivation as a persistent-access threat tier, not a nuisance tier — their restraint in avoiding disruption does not equate to lower risk.

Key Takeaways

  1. The Belarusian Cyber Partisans have confirmed breaching the Moscow Department of Health's network in 2023, corroborating independent findings from Russian security firm Solar.
  2. The group achieved administrator-level access across infrastructure connected to additional government and healthcare systems, but says it did not maintain long-term access because the target was a low priority.
  3. Solar's forensic analysis points to a nearly two-year undetected presence, with the earliest identified evidence dating to early 2024 — a timeline that doesn't perfectly match the attackers' own account.
  4. The intrusion involved Vasilek, a Telegram-controlled Windows backdoor capable of command execution, file transfer, screenshot capture, and keylogging, alongside persistence via rogue Windows services and a replaced vmtools.dll.
  5. No data destruction or operational disruption was reported, suggesting an intelligence-gathering motive — the group has said medical data could help it assess Russian military casualties from the war in Ukraine.
  6. Russia's Supreme Court designated the Cyber Partisans an "extremist organization" in July 2026, underscoring the escalating legal and geopolitical stakes around hacktivist operations tied to the Russia-Ukraine conflict.

Sources