Belarusian hacktivists spent two years inside Russian healthcare network, researchers say
A Belarusian activist hacking group reportedly spent nearly two years inside the network of a Russi 2026-10-5 14:18:15 Author: therecord.media(查看原文) 阅读量:2 收藏

A Belarusian activist hacking group reportedly spent nearly two years inside the network of a Russian healthcare organization, potentially gaining access to sensitive medical data, according to new research.

Russian cybersecurity firm Solar, a subsidiary of state-controlled telecom giant Rostelecom, said it discovered the intrusion in December 2025 but traced the earliest signs of the compromise to early 2024.

In a report released last week, researchers attributed the attack to the Belarusian Cyber Partisans, a group best known for disruptive attacks against government agencies and businesses in Belarus and Russia.

The targeted organization was not identified, but Solar said it operated extensive infrastructure with connections to numerous other healthcare organizations, potentially giving the hackers opportunities to use the compromised network to reach additional targets.

The hackers accessed sensitive medical data but did not disrupt or destroy the organization’s systems during two years in the network, according to the researchers.

“We believe the lack of destructive activity was linked to the value of maintaining this access for further espionage and trusted-relationship attacks,” they added.

In a trusted-relationship attack, hackers first compromise an organization that another potential victim already trusts and then exploit that connection to gain access to the ultimate target.

Among the tools used in the intrusion was Vasilek, a Windows backdoor that communicates with its operators through Telegram. The malware was first documented by Kaspersky in 2025, although Solar said the version it examined was newer.

Once installed, Vasilek can collect information about an infected computer, execute Windows commands, launch and terminate processes, transfer files, capture screenshots and record keystrokes. It can also update or delete itself.

Solar said restrictions on Telegram in Russia made communications between Vasilek and its command-and-control infrastructure less reliable. But the researchers said hackers can switch to other communication methods.

The Belarusian Cyber Partisans did not respond to a request for comment about the attack at the time of publication.

'Extremist' hackers

The group emerged following mass protests against Belarusian President Alexander Lukashenko after the country’s disputed 2020 presidential election, which Western governments rejected as fraudulent.

The Cyber Partisans have since claimed responsibility for some of the largest cyberattacks against the Belarusian government, including operations targeting state institutions and the country’s railway system. 

Since the start of the Ukraine war, the group has also increasingly targeted Russian organizations, including in operations aimed at stealing intelligence and disrupting operations.

Russia’s Supreme Court in July designated the Cyber Partisans an “extremist organization,” accusing the group of seeking to destabilize Russia and Belarus and overthrow the Belarusian government through unconstitutional means.

It was the first time Russia had applied the extremist designation to a hacking group.

“They can’t stop us, so they’re at least doing something to show they’re useful,” the Cyber Partisans said in response to the ruling. “And we will keep destabilizing the dictatorship!”

Recorded Future

No previous article

No new articles

Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.


文章来源: https://therecord.media/belarusian-hacktivists-two-years-Russian-healthcare-network
如有侵权请联系:admin#unsafe.sh