Hackers Hide Vasilek Backdoor Inside VMware Tools to Target Medical Organizations
Partisan Zmiy hid the Vasilek backdoor in VMware Tools during a two-year medical-organization intrusion.
Solar 4RAYS investigated a roughly two-year intrusion at a medical organization in which attackers hid the Vasilek backdoor inside a legitimate but unused VMware Tools installation. Earliest evidence is from early 2024 and includes remote command execution, Remote Desktop, and Windows file sharing; the initial entry point was not established. Shortly before discovery in December 2025, attackers replaced a signed VMware library with unsigned code and used scheduled services, timestomping, and a computer-name check. Vasilek 1.5.8 exposes 59 commands, including execution, file transfer, keylogging, screenshots, clipboard capture, and mouse input, controlled through Telegram, with DNSCat2, PartisanDNS, and a GOST-plus-3proxy chain as alternates. Sensitive medical data was exposed while systems stayed online, and overlapping infrastructure was linked to Partisan Zmiy.
- Intrusion evidence dates to early 2024 and lasted about two years.
- Attackers replaced a legitimate VMware library inside an unused Tools install.
- Vasilek 1.5.8 offers 59 commands, including keylogging and screen capture.
- Operators used Telegram plus DNSCat2, PartisanDNS, and GOST proxy tunnels.
- Solar 4RAYS links overlapping infrastructure and techniques to Partisan Zmiy.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | 0ce.org | -control domain detected in the incident. Historical domain 0ce[.]org Previously reported domain included for infrastructure co |
| domain | 3a01.net | n included for infrastructure comparison. Historical domain 3a01[.]net Previously reported domain included for infrastructure co |
| domain | 7cp.org | n included for infrastructure comparison. Historical domain 7cp[.]org Previously reported domain included for infrastructure co |
| domain | 89e.org | ain c-oh[.]com Network indicator published by Solar. Domain 89e[.]org Network indicator published by Solar. Domain parker-inc[. |
| domain | 91j.org | n included for infrastructure comparison. Historical domain 91j[.]org Previously reported domain included for infrastructure co |
| domain | c0ce.org | rker-inc[.]com Network indicator published by Solar. Domain c0ce[.]org DNSCat2 command-and-control domain detected in the incide |
| domain | c-oh.com |
Full article1,715 words · extracted from cybersecuritynews.com · click to collapse
Hackers concealed the Vasilek backdoor inside an existing VMware Tools installation during a prolonged intrusion at a medical organization.
The attackers maintained access for approximately two years, exposing sensitive medical information while leaving systems operational rather than launching a destructive attack.
The earliest evidence dates to early 2024. Investigators found signs of remote command execution, followed by movement through legitimate remote desktop access and Windows file sharing.
The report does not establish the original entry point, so phishing or vulnerability exploitation cannot be confirmed. Solar 4RAYS researchers identified an updated Vasilek build and a previously undocumented loader during an investigation that began in December 2025.
Solar said in a report shared with Cyber Security News (CSN) that overlapping infrastructure and techniques linked the intrusion to Partisan Zmiy.
The organization maintained two-way trust relationships with numerous subsidiary medical institutions. Researchers believe that access encouraged espionage over disruption, creating opportunities to reach connected organizations.
The case adds to concerns highlighted by backdoors targeting healthcare organizations that also conceal malicious activity behind familiar software and network services.
Hackers Hide Vasilek Backdoor Inside VMware Tools
VMware Tools had been installed legitimately long before the intrusion, but administrators were not using it. Its installation directory became a trusted yet unmonitored location where attackers placed malicious components with names resembling genuine virtualization software.
The report describes abuse of that installation, not a compromised vendor update. Shortly before discovery in December 2025, the attackers replaced a legitimate VMware library with malicious code and preserved the original under another name, apparently to allow restoration.
The replacement lacked a digital signature, unlike the genuine library. Solar describes the substitution as a mechanism for maintaining access.
This use of familiar software locations echoes malware hiding beside software in other backdoor research, although the campaigns are separate.
Investigators also found Windows services with plausible display names, allowing malicious libraries and the custom loader to blend into routine service listings.
.webp)
The loader launched tools according to a fixed schedule. One GOST tunnel operated every Saturday from 10 p.m. to 11 p.m., while another tunnel and Vasilek started once, eight hours after the service began.
Researchers interpreted the limited evening window as a likely backup connection. Other details suggested deliberate concealment. Attackers altered file timestamps to resemble legitimate VMware components and reused the same paths for different tools.
The loader configuration also referenced a server-specific Windows update repository, indicating that deployment followed reconnaissance rather than relying entirely on generic settings.
Telegram Control and Detection Gaps
Vasilek is a 32-bit Windows backdoor first publicly described in 2025. Solar analyzed internal version 1.5.8, whose command table contained 59 entries, including aliases.
Its capabilities include executing commands, transferring files, recording keystrokes, capturing screenshots, collecting clipboard contents, and manipulating mouse input.
Operators issued instructions through a Telegram group using the public Bot API. They posted on behalf of the group to conceal their personal accounts, while the malware returned results to the same chat.
Corporate proxy settings helped its connections follow the route used by legitimate traffic. Telegram was only one access channel. DNSCat2, PartisanDNS, and a GOST-plus-3proxy chain provided alternatives, making a single blocked service insufficient.
Similar backdoors using DNS tunneling illustrate how attackers can hide control traffic within ordinary network activity, without establishing a connection between these campaigns.
The backdoor also checked the infected computer’s name before activating, hindering analysis elsewhere. Solar recommends checking signatures in trusted software directories and investigating antivirus alerts rather than simply deploying protection.
Responders should hunt for additional tunnels, proxy chains, lateral movement tools, and delayed destructive payloads. Security logs preserved service creation events and traces of remote command execution, giving investigators evidence to reconstruct parts of the intrusion after the attackers had already changed files and settings.
The indicators below retain the source’s exact values. Solar’s narrative associates the substituted VMware library with Vasilek, but its detailed indicator appendix labels that sample as loading PartisanDNS.
Both descriptions are preserved rather than silently reconciled; shared hosting addresses and legitimate artifacts also require contextual interpretation.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| MD5 | a6af32b1381d8985049e2d5ec1889bd9 | PartisanDNS sample associated with the first listed system library. |
| MD5 | 338f7eafdfe45e93e57889ebd064d0d5 | UPX-packed DNSCat2 sample appearing under two library paths. |
| MD5 | 39e64553b7ddf579240e6642042e6840 | UPX-packed DNSCat2 sample. |
| MD5 | a6ce67f063fce60954bb6cea4c969aac | Additional PartisanDNS sample, including a backup copy. |
| MD5 | 1199d2f2b1a58435113555b02172bc79 | UPX-packed DNSCat2 sample. |
| MD5 | ccf73d3b1e9c625d79ce2c76650ca3e7 | Custom loader-scheduler. |
| MD5 | 6b21d7574b53b753bfdc2acf9c389a90 | 3proxy sample occupying a VMware-themed executable path. |
| MD5 | 560397a1bfb7fc32f7eeb7794183993d | Vasilek sample occupying the same executable path. |
| MD5 | 041a3ae432840507a755a79a22a1237a | GOST sample in the VMware Tools directory. |
| MD5 | 2538be4331f69dbf4a9b79565fd39581 | PartisanDNS executable. |
| MD5 | f34430fb88bda6c904c57facab761fc2 | GOST sample in the WSUS repository, deleted before examination. |
| MD5 | 86f330eb072216ffc807aff4013950f9 | Substituted VMware library; appendix identifies it as loading PartisanDNS. |
| SHA-1 | bdeac4b8e9a3c48661adf0c2ee5f05b58cee76eb | PartisanDNS sample. |
| SHA-1 | ed999aaaf1d032c76a51f4aececb99d06c371b33 | UPX-packed DNSCat2 sample appearing under two library paths. |
| SHA-1 | cd61f92873625dd25a31f414617347d1fa132747 | UPX-packed DNSCat2 sample. |
| SHA-1 | 56df605a33fb77c91bdb92033efe983f336deb23 | Additional PartisanDNS sample. |
| SHA-1 | efe3503bd021de67e884878c6de1e8b110ed2ee7 | UPX-packed DNSCat2 sample. |
| SHA-1 | 42f5cbbe0feba3e31ac8642791dd48eef8eae123 | Custom loader-scheduler. |
| SHA-1 | 3b1424176c9c1083b79961783b38f5176ff99fee | 3proxy sample. |
| SHA-1 | 3834c4c83cf9758385347a8b34a3e20e17aced3b | Vasilek sample. |
| SHA-1 | f2fb4a3ba5802df7ae83ac7fb362bce45223312b | GOST sample in the VMware Tools directory. |
| SHA-1 | d93f810fa02c3d4391810ab512519d89f2f0ceee | PartisanDNS executable. |
| SHA-1 | c4e623ab0a15db0896bf8a68eb9b45ebe6ae2f28 | Unknown WSUS-themed file, deleted before examination. |
| SHA-1 | 23831129ad88da40cd0bdeae2350f956ca0b2db2 | GOST sample in the WSUS repository. |
| SHA-1 | 4335474d9fd48d7d28e244802e210f1e78dc2f3a | Substituted VMware library. |
| SHA-256 | cc8c707bf49c0cdb79b806d41df6254efc0e9f566a02d223871550f414469d13 | PartisanDNS sample. |
| SHA-256 | e5c6b6d37ff168def37dfd86c636e512be3ed7ead9a2dc93d5c741c42b47c1f1 | UPX-packed DNSCat2 sample appearing under two library paths. |
| SHA-256 | 07381d79670129277211a4373e5518799a54b427946602539463ec2dd9cdb5e7 | UPX-packed DNSCat2 sample. |
| SHA-256 | 4f0e23a83d83d901c76353d8b9b6ee2940eb63d531ad15f736193903b5c7c8c3 | Additional PartisanDNS sample. |
| SHA-256 | 8c37c4b1f168219a1ce495c9822730981b20ff03d937ddcd8795fca14a9b7869 | UPX-packed DNSCat2 sample. |
| SHA-256 | 5bc4fa9916c0883d45cb85639e328ed484dc75f4dfda294eb52f4b8b612889f2 | Custom loader-scheduler. |
| SHA-256 | c499fab59acbb1750e1e0e5a3c51d119ccd6374e5f0b45639f29598720222766 | 3proxy sample. |
| SHA-256 | 87e713f9b6ae14d97d3fa4d1a882c029e7e963d844d9c93ea383cab3d46a949c | Vasilek sample. |
| SHA-256 | d7aedc020ce832334abf0d03986da31f41cb2191355f25b17989dcfa8bb2775b | GOST sample in the VMware Tools directory. |
| SHA-256 | e55431d6f15aa78ada3f60ed30a3f32b444b952bdc53a652546c1820f8bfa513 | PartisanDNS executable. |
| SHA-256 | 5076286c26f2a5c7dd7f507365fe404db2b05d39b350c463faa053baa37b3742 | GOST sample in the WSUS repository. |
| SHA-256 | 125ead2c3b1d0f7aee03d13b927744ec8dc1d046912ce73efc9c5a10243b99dc | Substituted VMware library. |
| IP address | 172.67.210[.]25 | Source-listed network indicator, labeled Cloudflare; shared infrastructure requires contextual assessment. |
| IP address | 104.21.34[.]242 | Source-listed network indicator, labeled Cloudflare; shared infrastructure requires contextual assessment. |
| IP address | 199.59.243[.]228 | Source-listed network indicator, labeled Amazon. |
| Domain | okkgb[.]com | Network indicator published by Solar. |
| Domain | c-oh[.]com | Network indicator published by Solar. |
| Domain | 89e[.]org | Network indicator published by Solar. |
| Domain | parker-inc[.]com | Network indicator published by Solar. |
| Domain | c0ce[.]org | DNSCat2 command-and-control domain detected in the incident. |
| Domain | p7cp[.]org | DNSCat2 command-and-control domain detected in the incident. |
| Domain | gov-by[.]com | Reused command-and-control domain overlapping earlier reporting. |
| Domain | f91j[.]org | DNSCat2 command-and-control domain detected in the incident. |
| Domain | w3a01[.]net | DNSCat2 command-and-control domain detected in the incident. |
| Historical domain | 0ce[.]org | Previously reported domain included for infrastructure comparison. |
| Historical domain | 7cp[.]org | Previously reported domain included for infrastructure comparison. |
| Historical domain | 3a01[.]net | Previously reported domain included for infrastructure comparison. |
| Historical domain | 91j[.]org | Previously reported domain included for infrastructure comparison. |
| DGA domain | vpnosljjk[.]pro | PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]top | PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]link | PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]cyou | PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]pro | PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]me | PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]my | PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]buzz | PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]info | PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]space | PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]in | PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]sbs | PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]work | PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]casa | PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]lol | PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]lat | PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]net | PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]org | PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]com | PartisanDNS domain-generation indicator. |
| File path | C:\Windows\System32\msadcs32.dll | PartisanDNS library; multiple samples occupied this path. |
| File path | C:\Windows\System32\msadcs32.bak | Backup-path copy of a PartisanDNS sample. |
| File path | C:\Windows\System32\tpvmmon.dll | DNSCat2 library launched through a Windows service. |
| File path | C:\Windows\system32\omega.dll | Additional path for the same UPX-packed DNSCat2 sample. |
| File path | C:\Windows\System32\aweman32.dll | DNSCat2 library launched through a Windows service. |
| File path | C:\Windows\system32\uplay_r164.dll | UPX-packed DNSCat2 library. |
| File path | C:\Program Files\VMware\VMware Tools\authd.exe | Custom loader-scheduler masquerading as a VMware component. |
| File path | C:\Program Files\VMware\VMware Tools\rpctool32.exe | Path occupied by both 3proxy and Vasilek samples during the campaign. |
| File path | C:\Program Files\VMware\VMware Tools\vmtoolsd32.exe | GOST executable with altered timestamps. |
| File path | C:\Windows\fstab.exe | PartisanDNS executable. |
| File path | C:\Update\169\WSUSSCAN.exe | Unknown file deleted before investigation. |
| File path | E:\WSUS\UpdateServicesPackages\WsusService.exe | GOST executable disguised as a WSUS component. |
| File path | C:\Program Files\VMware\VMware Tools\vmtools.dll | Replaced VMware library; narrative links it to Vasilek, appendix says it loads PartisanDNS. |
| File path | C:\Windows\System32\vmtoolsd.exe | Executable associated with a service displayed as “VMware Service”; payload unspecified. |
| File path | C:\Program Files\VMware\VMware Tools\gost.yml | GOST proxy configuration recovered in command-and-control exchanges. |
| File name | vmtoolsd.dll | Original legitimate VMware library renamed and retained, apparently for restoration. |
| File name | vmtoolsd.exe | Legitimate VMware component name imitated by attacker tooling; not independently malicious. |
| File name | rpctool.exe | Legitimate VMware component name imitated by attacker tooling; not independently malicious. |
| File name | new.bak | Downloaded replacement backdoor used during self-update. |
| File-name pattern | old-<timestamp>.bak | Previous backdoor executable renamed during self-update. |
| File-name notation | old-.bak | Source shorthand for the replaced backdoor backup. |
| File name | MySong.mp3 | Hardcoded audio filename referenced by an apparent developer debugging function. |
| File-name template | [HOSTNAME]-tun.yml | Telegram attachment filename shown in the recovered exchange. |
| File-name pattern | C:\Windows\__<unix timestamp>.<microseconds> | Remote command-output artifact consistent with Impacket execution. |
| UNC path pattern | \\127.0.0.1\ADMIN$\__<unix timestamp>.<microseconds> | Remote command-output destination; loopback address is not external attacker infrastructure. |
| UNC path pattern | \\127.0.0.1\ADMIN$\__<ts>.<us> | Alternate notation appearing in the source’s MITRE matrix. |
| Tool filename | wmiexec.py | Impacket tool associated with the observed command-output pattern; legitimate dual-use tool. |
| Executable name | cmd.exe | Windows command interpreter used in observed execution; not independently malicious. |
| Service name | tpvmmon | Malicious service displayed as “Windows Insiders Service.” |
| Service name | aweman32 | Malicious service displayed as “Windows Channels Service.” |
| Service name | msadcs32 | Malicious service displayed as “Sybase Inc. Product File.” |
| Service name | uplay_r164 | Malicious service displayed as “Access FT Imager Service.” |
| Service name | vmauad | Loader service displayed as “VMware Auth Adapter.” |
| Service artifact | AppMgmt | Legitimate Windows service whose parameters were apparently temporarily altered. |
| Registry path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System | Legitimate policy location inspected during privilege-elevation attempts. |
| Registry value | ConsentPromptBehaviorAdmin | UAC policy value checked by the backdoor; not independently malicious. |
| URL template | https://api.telegram.org/bot<token>/<method> | Legitimate Telegram API endpoint template assembled for command and control; token and method are placeholders. |
| Telegram chat ID | -1002113172843 | Group identifier visible in recovered command-and-control exchanges. |
| Telegram account name | GroupAnonymousBot | Legitimate Telegram identity used to post commands anonymously on behalf of the group. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.