Skip to content

Security1 publisher2 min readPublished

Belarusian Cyber Partisans spent nearly two years inside a Russian healthcare network, Solar says

Security firm Solar says Belarusian Cyber Partisans were inside an unnamed Russian healthcare network from early 2024 until its discovery in December 2025. That network connects to numerous other providers, and Solar says the foothold gave the intruders a possible route into them.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Belarusian Cyber Partisans spent nearly two years inside a Russian healthcare network, Solar says
Generated illustration

What happened

  • Solar attributes the intrusion to a group best known for disruptive attacks on government agencies and businesses in Belarus and Russia.
  • The intruders used a newer version of Vasilek, a Windows backdoor controlled over Telegram that Kaspersky first documented in 2025.
  • Vasilek can profile a host, run Windows commands, start and kill processes, move files, take screenshots, log keystrokes, and update or delete itself.
  • Russia's Supreme Court designated the Cyber Partisans an extremist organization in July, the first time Russia applied that label to a hacking group.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Providers that trust the compromised network are open to trusted-relationship attacks, in which the intruder comes in over a connection the target already accepts.
  • decision With the victim unnamed, connected Russian providers have to decide whether to review partner links without knowing from the public record which partner was breached.
  • constraint An intruder who reads data and breaks nothing causes no outage, so finding one depends on hunting for the implant or its traffic.
  • constraint Russia's Telegram restrictions degrade Vasilek's command channel without closing it, since Solar says the operators can switch to other methods.

Solar's researchers presented their explanation for the group's restraint as a belief. "We believe the lack of destructive activity was linked to the value of maintaining this access for further espionage and trusted-relationship attacks," they said [7]. The facts they observed are narrower. The intruders accessed sensitive medical data and did not disrupt or destroy the organization's systems [6]. Solar described the connected providers as an opportunity the hackers had. The Record's account of the report does not say the group used the foothold to break into any of them [5].

Solar is a subsidiary of state-controlled telecom Rostelecom [3]. It attributed the intrusion to the Cyber Partisans in a report released last week [1]. The group did not respond to The Record's request for comment [12]. The attribution, the dwell time and the motive all rest on Solar's evidence [3][1][7].

The Cyber Partisans formed after mass protests against Belarusian President Alexander Lukashenko over the disputed 2020 election [13]. Their largest claimed operations hit Belarusian state institutions and the country's railway system [14]. Since the war in Ukraine began, the group has increasingly gone after Russian organizations, in operations aimed at stealing intelligence as well as disrupting them [15]. A two-year collection operation inside a medical network fits the intelligence side of that record. One case is not enough to show the group now prefers long, quiet access to disruption.

The group replied to the Supreme Court ruling against it. "They can't stop us, so they're at least doing something to show they're useful," it said [17].

What to watch

  • Whether Solar or another firm reports a second healthcare organization reached through the victim's connections.
  • A Vasilek variant observed using a command channel other than Telegram inside Russian networks.
  • Any claim, denial or data release from the Cyber Partisans about the healthcare intrusion.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories