Partisan Zmiy Malware Campaign Uses Telegram and DNS Tunneling to Target Healthcare Networks
Cyber Partisans maintained roughly two-year espionage access to a medical organization using an updated Vasilek Telegram-controlled backdoor, GOST tunnels, and DNS tunneling.
Solar 4RAYS documented a Cyber Partisans (Partisan Zmiy) intrusion into a medical organization with earliest compromise evidence from early 2024, investigated starting December 2025. The toolkit included Vasilek 1.5.8, a 32-bit Windows backdoor with 59 commands controlled via Telegram Bot API long polling, and a new authd.exe loader masquerading as a VMware Auth Adapter service. Redundant C2 came via DNSCat2, PartisanDNS, and a GOST-3proxy chain, with persistence through Windows services (Event ID 7045) and DLL side-loading of vmtools.dll. Attribution rested on Vasilek malware and infrastructure overlapping prior Cyber Partisans research, including reused domain gov-by[.]com.
- Compromise traced to early 2024, about two years of espionage access without destructive activity
- Vasilek 1.5.8 backdoor executes 59 commands via Telegram Bot API, restricted by hostname hash
- authd.exe loader masqueraded as VMware Auth Adapter service inside legitimate VMware Tools directory
- DNSCat2, PartisanDNS, and GOST-3proxy chains provided redundant backup C2 channels
- Attribution to Cyber Partisans based on Vasilek malware and overlapping command infrastructure
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | c0ce.org | om automatically removing access. Observed domains included c0ce[.]org, p7cp[.]org, w3a01[.]net, f91j[.]org, and the reused gov- |
| domain | f91j.org | erved domains included c0ce[.]org, p7cp[.]org, w3a01[.]net, f91j[.]org, and the reused gov-by[.]com. These indicators overlapped |
| domain | gov-by.com | [.]org, p7cp[.]org, w3a01[.]net, f91j[.]org, and the reused gov-by[.]com. These indicators overlapped with, or closely resembled, |
| domain | p7cp.org | ally removing access. Observed domains included c0ce[.]org, p7cp[.]org, w3a01[.]net, f91j[.]org, and the reused gov-by[.]com. Th |
| domain | w3a01.net | g access. Observed domains included c0ce[.]org, p7cp[.]org, w3a01[.]net, f91j[.]org, and the reused gov-by[.]com. These indicator |
| md5 | 1199d2f2b1a58435113555b02172bc79 | 79240e6642042e6840 MD5 a6ce67f063fce60954bb6cea4c969aac MD5 1199d2f2b1a58435113555b02172bc79 SHA1 bdeac4b8e9a3c48661adf0c2ee5f05b58cee76eb SHA1 ed999aaa |
| md5 |
Full article688 words · extracted from gbhackers.com · click to collapse
A prolonged Partisan Zmiy intrusion into a medical organization, exposing an updated malware toolkit that combined Telegram command channels, DNS tunneling, and scheduled payload execution.
Investigators joined the response in December 2025 and traced the earliest evidence of compromise to early 2024, indicating approximately two years of access without observed destructive activity.
The organization maintained extensive infrastructure and bidirectional trust relationships with subsidiary medical institutions.
Researchers assess that preserving these connections may have offered greater value for espionage and subsequent attacks than immediate disruption.
Attribution rested on Vasilek malware, overlapping command infrastructure, and established tactics associated with Cyber Partisans.
The investigation began after scanning activity originated from a subsidiary medical organization.
Historical antivirus detections identified Vasilek and GOST, while early command execution artifacts matched Impacket’s wmiexec.py: command output redirected through the localhost ADMIN$ share into timestamped files.
Attackers maintained persistence through Windows services and malicious DLLs masquerading as system components.
Service creation records remained in Windows System logs under Event ID 7045. Because operators repeatedly replaced payloads at identical paths, filenames alone could not reliably identify which tool had occupied each location.
A previously undescribed loader, authd.exe, ran as the “VMware Auth Adapter” service inside the legitimate VMware Tools directory.
It orchestrated GOST and Vasilek payloads concealed as vmtoolsd32.exe, rpctool32.exe, and WsusService.exe.
The Solar 4RAYS team encountered another attack, by Partisan Zmiy (the Cyber Partisans group is designated as extremist and its activities are banned in Russia), this time targeting a medical organization.
Partisan Zmiy Malware
The scheduler activated one GOST tunnel every Saturday between 22:00 and 23:00. Two additional payloads launched once, eight hours after service startup.
While analyzing the malicious activity, we discovered modifications to the registry key tags of the legitimate
AppMgmt service.

Researchers interpreted the restricted window as a likely backup channel and the delayed execution as an effort to separate malicious traffic from startup activity.
Shortly before discovery, operators replaced VMware’s signed vmtools.dll with an unsigned Vasilek library, retaining the original as vmtoolsd.dll.
The software directory was legitimate but operationally neglected, providing an effective concealment location.
Vasilek version 1.5.8 is a 32-bit Windows backdoor controlled through Telegram group messages.
Its command table contains 59 entries, including aliases, supporting shell execution, file transfers, screenshots, keylogging, clipboard collection, and process management.

Operators retrieved commands through getUpdates long polling and returned results using Telegram’s Bot API.
Group-based anonymous posting concealed the sender’s account, while task identifiers helped operators associate responses with individual commands.
Before execution, Vasilek compared a salted SHA-256 hostname hash against a hardcoded value, restricting operation to the intended machine.
OLLVM-based control-flow flattening, encrypted strings, and dynamically resolved APIs further complicated analysis.
Kaspersky ICS CERT’s June 2025 research previously documented Vasilek’s Telegram control architecture and hostname-dependent execution, establishing the technical baseline for this updated investigation.
Telegram was only one access route. DNSCat2, PartisanDNS, and a GOST–3proxy chain provided alternative connectivity, preventing disruption of one channel from automatically removing access.
Observed domains included c0ce[.]org, p7cp[.]org, w3a01[.]net, f91j[.]org, and the reused gov-by[.]com. These indicators overlapped with, or closely resembled, infrastructure documented in earlier Cyber Partisans research.
Investigators also found evidence suggesting temporary modification and restoration of the legitimate AppMgmt service.
Public tools such as NimExec support comparable service-path manipulation, although their availability does not establish their use in this incident.
The case underscores the importance of investigating recurring detections, auditing service changes, verifying signatures in trusted software directories, and correlating suspicious DNS traffic with unexpected messenger API connections across interconnected healthcare environments.
IOCs
| Hash type | Hash value |
|---|---|
| MD5 | a6af32b1381d8985049e2d5ec1889bd9 |
| MD5 | 338f7eafdfe45e93e57889ebd064d0d5 |
| MD5 | 39e64553b7ddf579240e6642042e6840 |
| MD5 | a6ce67f063fce60954bb6cea4c969aac |
| MD5 | 1199d2f2b1a58435113555b02172bc79 |
| SHA1 | bdeac4b8e9a3c48661adf0c2ee5f05b58cee76eb |
| SHA1 | ed999aaaf1d032c76a51f4aececb99d06c371b33 |
| SHA1 | cd61f92873625dd25a31f414617347d1fa132747 |
| SHA1 | 56df605a33fb77c91bdb92033efe983f336deb23 |
| SHA1 | efe3503bd021de67e884878c6de1e8b110ed2ee7 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.