Belarusian Hacktivists Confirm Years-Long Foothold in Russian Health Network
The Belarusian Cyber Partisans, a hacktivist collective formed in the wake of the 2020 protests against President Alexander Lukashenko, have publicly confirmed that they breached the network of the Moscow Department of Health in 2023, obtaining administrator-level access to infrastructure connected to other Russian government agencies and healthcare institutions. The group's admission, given to Recorded Future News (publisher of The Record), corroborates a separate report from Solar, the cybersecurity subsidiary of state-controlled telecom operator Rostelecom, which independently uncovered the intrusion and said forensic evidence showed the attackers' presence in the network for close to two years before it was identified.
Incident Details
| Attribute | Value |
|---|---|
| Threat actor | Belarusian Cyber Partisans (hacktivist collective) |
| Target | Moscow Department of Health (Russian state healthcare network) |
| Claimed initial access | 2023, per the Cyber Partisans |
| Discovered by | Solar (Rostelecom's cybersecurity subsidiary) |
| Researchers' earliest observed evidence | Early 2024 |
| Access level achieved | Administrator-level, across infrastructure linked to other government and healthcare systems |
| Backdoor identified | Vasilek (Windows malware, Telegram-based command-and-control) |
| Data impact | Accessed sensitive medical records; no reported destruction or operational disruption |
| Stated motive | Assessing Russian military casualties from the war in Ukraine |
| Legal status in Russia | Group designated an "extremist organization" by Russia's Supreme Court, July 2026 |
How It Happened
Who Are the Cyber Partisans
The Cyber Partisans emerged from the mass protest movement that followed Belarus's disputed 2020 presidential election, initially focused on disrupting Lukashenko-aligned government and security-service systems inside Belarus — including a previously reported intrusion against the Belarusian KGB and attacks on the national railway network timed to Russian troop movements. After Russia's full-scale invasion of Ukraine in 2022, the group expanded its targeting to Russian government and infrastructure networks, framing its operations as both anti-Lukashenko and anti-Kremlin activism. In July 2026, Russia's Supreme Court designated the Cyber Partisans an "extremist organization" — the first time Russia has applied that designation to a hacking group — to which the collective responded by saying it would continue operations against both governments.
The 2023 Intrusion
According to the group's own account, breaking into the Moscow Department of Health's network required little effort. The Cyber Partisans told Recorded Future News that the target "was not a priority" for them, which is why they did not retain persistent access, adding: "We gained full access to its entire infrastructure relatively quickly and with little effort." That access reportedly reached administrator-level privileges across an IT environment that extended beyond the health department itself, touching systems tied to other government agencies and additional healthcare organizations connected to the same network.
How Researchers Found It
Solar, operating as Rostelecom's security arm, identified the intrusion independently and published a report attributing the activity to the Cyber Partisans. Solar's investigators traced the earliest forensic signs of compromise to early 2024 — roughly a year after the date the hacktivists themselves cite for initial access — and assessed that the attackers had maintained a presence in the network for close to two years before detection. Researchers noted the intruders accessed sensitive medical information but did not destroy data or disrupt the health department's operations, a restraint Solar interpreted as consistent with an intelligence-gathering posture rather than disruptive hacktivism — maintaining the foothold "for further espionage and trusted-relationship attacks" against connected organizations.
The Vasilek Backdoor
Among the tools Solar recovered from the compromised environment was Vasilek, a Windows backdoor that uses Telegram for command-and-control communication. The malware was first documented by Kaspersky in 2025, but the sample found in the health department's network was a newer variant. Once deployed, Vasilek can collect host and system information, execute arbitrary Windows commands, launch and terminate processes, transfer files, capture screenshots, and log keystrokes, and it can update or delete itself to cover its tracks. Solar noted that Russia's restrictions on Telegram access have made the malware's C2 channel less reliable at times, though operators retain the ability to switch to alternative communication methods. Investigators also identified persistence mechanisms consistent with a methodical, long-term intrusion: registration of malicious Windows services, and replacement of vmtools.dll, a legitimate library associated with VMware Tools, to blend malicious code into trusted virtualization software on affected hosts.
A Timeline Gap Worth Noting
The Cyber Partisans' claim of 2023 access and Solar's forensic dating to early 2024 do not fully align. The discrepancy could reflect gaps in available log retention, an initial access stage that left little forensic trace before the tooling now attributed to the intrusion was deployed, or simply differing definitions of when "access" began versus when the specific artifacts Solar analyzed were first planted. Either reading still points to a multi-year, largely undetected presence inside a state healthcare network.
Impact Assessment
| Impact Area | Description |
|---|---|
| Confidentiality | Sensitive medical records and healthcare-network data were accessed and potentially exfiltrated |
| Scope of exposure | Access extended to systems connected to other Russian government agencies and healthcare institutions, beyond the Moscow Department of Health itself |
| Availability/Integrity | No reported data destruction or service disruption — consistent with a long-term espionage posture |
| Attribution confidence | High — corroborated independently by both the attacker (Cyber Partisans) and the defender-side researcher (Solar) |
| Strategic risk | Demonstrates that Russian state healthcare infrastructure, often treated as a lower-priority target, can provide administrator-level pivot points into interconnected government networks |
| Detection latency | Up to roughly two years between initial compromise and discovery, highlighting weak long-term threat hunting in the targeted environment |
Recommendations
For Healthcare and Government Network Administrators
- Segment healthcare IT environments from broader government networks; treat shared infrastructure between a health department and other agencies as a high-value pivot path requiring its own monitoring boundary.
- Audit
vmtools.dlland other VMware Tools components against known-good hashes across virtualized hosts — DLL replacement in trusted virtualization software is a persistence technique that evades casual review. - Inventory and monitor for unauthorized Windows services, a common low-effort persistence mechanism that can go unnoticed for years without routine service-baseline audits.
For Security Teams
- Add detection logic for Telegram-based C2 traffic, including Telegram Bot API calls originating from server or workstation assets that have no legitimate business reason to use the service.
- Hunt for
Vasilek-associated indicators (Kaspersky's 2025 writeup and Solar's newer analysis) across EDR telemetry, particularly process trees showing screenshot capture, keylogging hooks, or arbitrary command execution from unexpected parent processes. - Extend log retention windows for critical infrastructure. A detection gap of up to two years, as seen here, is only closeable with retained historical telemetry, not just real-time alerting.
For Organizations Operating Interconnected Networks
- Reassess trust relationships between departments and affiliated organizations sharing infrastructure; administrator-level compromise of one connected entity can expose all of them.
- Treat hacktivist groups with sustained operational capability and geopolitical motivation as a persistent-access threat tier, not a nuisance tier — their restraint in avoiding disruption does not equate to lower risk.
Key Takeaways
- The Belarusian Cyber Partisans have confirmed breaching the Moscow Department of Health's network in 2023, corroborating independent findings from Russian security firm Solar.
- The group achieved administrator-level access across infrastructure connected to additional government and healthcare systems, but says it did not maintain long-term access because the target was a low priority.
- Solar's forensic analysis points to a nearly two-year undetected presence, with the earliest identified evidence dating to early 2024 — a timeline that doesn't perfectly match the attackers' own account.
- The intrusion involved
Vasilek, a Telegram-controlled Windows backdoor capable of command execution, file transfer, screenshot capture, and keylogging, alongside persistence via rogue Windows services and a replacedvmtools.dll. - No data destruction or operational disruption was reported, suggesting an intelligence-gathering motive — the group has said medical data could help it assess Russian military casualties from the war in Ukraine.
- Russia's Supreme Court designated the Cyber Partisans an "extremist organization" in July 2026, underscoring the escalating legal and geopolitical stakes around hacktivist operations tied to the Russia-Ukraine conflict.