Hackers Hide Vasilek Backdoor Inside VMware Tools to Target Medical Organizations
Partisan Zmiy hid the Vasilek backdoor in VMware Tools during a two-year medical-organization intrusion.
Solar 4RAYS investigated a roughly two-year intrusion at a medical organization in which attackers hid the Vasilek backdoor inside a legitimate but unused VMware Tools installation. Earliest evidence is from early 2024 and includes remote command execution, Remote Desktop, and Windows file sharing; the initial entry point was not established. Shortly before discovery in December 2025, attackers replaced a signed VMware library with unsigned code and used scheduled services, timestomping, and a computer-name check. Vasilek 1.5.8 exposes 59 commands, including execution, file transfer, keylogging, screenshots, clipboard capture, and mouse input, controlled through Telegram, with DNSCat2, PartisanDNS, and a GOST-plus-3proxy chain as alternates. Sensitive medical data was exposed while systems stayed online, and overlapping infrastructure was linked to Partisan Zmiy.