Belarusian hacktivists spent two years inside Russian healthcare network
Researchers at Solar, a Rostelecom subsidiary, found an intrusion into a Russian healthcare organization's network in December 2025, with traces dating back to early 2024. The attack is attributed to the Belarusian Cyber Partisans, who accessed sensitive medical data but did not disrupt systems, instead maintaining access for espionage and trusted-relationship attacks. The toolkit included Vasilek, a Windows backdoor communicating via Telegram.
- The intrusion lasted nearly two years, from early 2024 to December 2025
- The attack is attributed to the Belarusian Cyber Partisans
- Systems were not disrupted; access was kept for espionage and trusted-relationship attacks
- Hackers used the Vasilek backdoor controlled via Telegram
Read next
Security