Belarusian hacktivists spent two years inside Russian healthcare network, researchers say
What happened
Russian cybersecurity firm Solar, a subsidiary of state-controlled telecom giant Rostelecom, said it discovered the intrusion in December 2025 but traced the earliest signs of the compromise to early 2024. In a report released last week, researchers attributed the attack to the Belarusian Cyber Partisans , a group best known for disruptive attacks against government agencies and businesses in Belarus and Russia.
The targeted organization was not identified, but Solar said it operated extensive infrastructure with connections to numerous other healthcare organizations, potentially giving the hackers opportunities to use the compromised network to reach additional targets. Russian cybersecurity researchers attributed a quiet two-year espionage campaign to the Belarusian Cyber Partisans, a group better known for public attacks against governments and infrastructure.
The hackers accessed sensitive medical data but did not disrupt or destroy the organization’s systems during two years in the network, according to the researchers. Among the tools used in the intrusion was Vasilek, a Windows backdoor (a hidden way into a system that bypasses its login) that communicates with its operators through Telegram. It can also update or delete itself.
Key facts
- In a report — released: last week, researchers attributed the attack to the Belarusian Cyber Partisans , a group best known for disruptive attacks against government agencies and businesses in Belarus and Russia
Sources & evidence
- The Record Reporting source
Belarusian hacktivists spent two years inside Russian healthcare network, researchers say ↗
https://therecord.media/belarusian-hacktivists-two-years-Russian-healthcare-network