Partisan Zmiy kept access to healthcare network for nearly two years
Solar 4RAYS detailed the Partisan Zmiy intrusion: an attacker held access to a healthcare network for about two years, reaching domain controllers and sensitive medical data. The operation used Vasilek, RDP/SMB, Telegram C2 and DNS tunneling; data exfiltration remains unconfirmed.
- Access persisted roughly two years, from early 2024 to the December 2025 investigation
- Persistence relied on a replaced vmtools.dll, a custom loader and Windows services
- C2 used the Telegram Bot API, DNSCat2/PartisanDNS and GOST with 3proxy
- Domain controllers and sensitive medical data were reached; exfiltration unconfirmed
Read next
Security