Partisan Zmiy hackers maintained access to a healthcare organization for nearly two years, using the Telegram-controlled Vasilek backdoor alongside DNS tunnels and proxy tools. Solar 4RAYS investigators found evidence dating to early 2024 after joining the investigation in December 2025.
The investigation began when a subsidiary medical organization scanned the customer’s domain. Analysts discovered numerous antivirus alerts, including detections for Vasilek and GOST.
Overlapping infrastructure and attack techniques supported attribution to Partisan Zmiy, also known as Cyber Partisans.
Despite gaining access to domain controllers and centralized management systems, the attackers did not launch destructive operations.
Researchers believe the organization’s sensitive medical information and trusted connections with affiliated healthcare networks made continued espionage more valuable.
Vasilek Backdoor Targets Healthcare
The attackers maintained persistence through Windows services disguised as legitimate software. Names such as “Windows Insiders Service” and “VMware Auth Adapter” helped malicious components blend into routine service listings.
Investigators also identified a previously undocumented loader, authd.exe, inside the VMware Tools directory.
The software had been legitimately installed long before the intrusion but was no longer actively used by administrators, creating an overlooked location for malicious files.

The loader launched payloads using interval timers and cron schedules. One GOST tunnel operated every Saturday from 10 p.m. to 11 p.m. Another GOST instance and Vasilek started once, eight hours after the service launched.
Researchers believe these limited operating windows and delayed starts reduced opportunities for detection. Payload names also copied VMware Tools and Windows Server Update Services components.
The attackers replaced vmtools.dll shortly before discovery and preserved the original library under another name. The replacement was unsigned, unlike the legitimate VMware file.
Earlier evidence included command output redirected into the ADMIN$ share, a pattern associated with Impacket’s wmiexec.py. Investigators also observed lateral movement through legitimate RDP access and SMB command execution.
Vasilek is a 32-bit Windows backdoor that receives commands through a Telegram group and sends results back through the public Bot API. Kaspersky ICS CERT first publicly described the malware in June 2025.
Solar examined version 1.5.8, which contained 59 command entries, including aliases. Its capabilities included shell execution, file transfers, screenshots, clipboard collection, keylogging, and simulated mouse input. Compared with version 1.5.4, researchers found one additional command, move_cursor.
Before operating, Vasilek checks a salted SHA-256 hash of the computer name against an embedded value. A mismatch stops execution, limiting activity outside the intended target, Solar said.
Indicators of Compromise
| File path | SHA-256 | Reported tool |
|---|---|---|
C:\Windows\System32\msadcs32.dll | cc8c707bf49c0cdb79b806d41df6254efc0e9f566a02d223871550f414469d13 | PartisanDNS |
C:\Windows\System32\tpvmmon.dll; C:\Windows\system32\omega.dll | e5c6b6d37ff168def37dfd86c636e512be3e |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team