Partisan Zmiy Malware Campaign Uses Telegram and DNS Tunneling to Target Healthcare Networks
Cyber Partisans maintained roughly two-year espionage access to a medical organization using an updated Vasilek Telegram-controlled backdoor, GOST tunnels, and DNS tunneling.
Solar 4RAYS documented a Cyber Partisans (Partisan Zmiy) intrusion into a medical organization with earliest compromise evidence from early 2024, investigated starting December 2025. The toolkit included Vasilek 1.5.8, a 32-bit Windows backdoor with 59 commands controlled via Telegram Bot API long polling, and a new authd.exe loader masquerading as a VMware Auth Adapter service. Redundant C2 came via DNSCat2, PartisanDNS, and a GOST-3proxy chain, with persistence through Windows services (Event ID 7045) and DLL side-loading of vmtools.dll. Attribution rested on Vasilek malware and infrastructure overlapping prior Cyber Partisans research, including reused domain gov-by[.]com.