Partisan Zmiy Hid Vasilek Backdoor Inside VMware Tools in Two-Year Medical Organization Espionage
Solar 4RAYS detailed a roughly two-year Cyber Partisans (Partisan Zmiy) intrusion at a medical organization in which the Telegram-controlled Vasilek 1.5.8 backdoor was hidden in an unused VMware Tools installation, backed by redundant DNS-tunneling and proxy…
Solar 4RAYS investigated a roughly two-year intrusion at a medical organization, with the earliest compromise evidence from early 2024 and the investigation beginning in December 2025; the initial entry point was not established. Attackers hid Vasilek 1.5.8 — a 32-bit Windows backdoor exposing 59 commands, including execution, file transfer, keylogging, screenshots, clipboard capture, and mouse input — inside a legitimate but unused VMware Tools installation, using a new authd.exe loader masquerading as a VMware Auth Adapter service and DLL side-loading of vmtools.dll. Shortly before discovery in December 2025, attackers replaced a signed VMware library with unsigned code and used scheduled services, timestomping, and a computer-name check, with persistence via Windows services (Event ID 7045). Vasilek was controlled through Telegram Bot API long polling, restricted by a hostname hash, with redundant C2 via DNSCat2, PartisanDNS, and a GOST-3proxy chain. Observed activity included remote command execution, Remote Desktop, and Windows file sharing. Sensitive medical data was exposed while systems remained online, and GBHackers characterizes the operation as espionage with no destructive activity. Attribution to Cyber Partisans (Partisan Zmiy) rests on the Vasilek malware and overlapping infrastructure from prior research, including the reused domain gov-by[.]com. The two reports agree on all core details.
- Earliest evidence of compromise dates to early 2024; Solar 4RAYS began investigating in December 2025, and the initial entry point was not established.
- Vasilek 1.5.8 is a 32-bit Windows backdoor with 59 commands, including execution, file transfer, keylogging, screenshots, clipboard capture, and mouse input.
- The backdoor was hidden in a legitimate but unused VMware Tools installation via an authd.exe loader masquerading as a VMware Auth Adapter service and DLL side-loading of vmtools.dll; a signed VMware library was replaced with unsigned code…
- Persistence and stealth relied on Windows services (Event ID 7045), scheduled services, timestomping, and a computer-name check.
- Primary C2 used Telegram Bot API long polling restricted by a hostname hash, with backup channels via DNSCat2, PartisanDNS, and a GOST-3proxy chain.
- Sensitive medical data was exposed while systems stayed online; GBHackers reports the access was espionage with no destructive activity.
- Attribution to Cyber Partisans (Partisan Zmiy) is based on the Vasilek malware and overlapping command infrastructure, including the reused domain gov-by[.]com.
Coverage timelineoldest first · each row is one article
- · 2d agoHackers Hide Vasilek Backdoor Inside VMware Tools to Target Medical Organizations
Cyber Security News· 74
Partisan Zmiy hid the Vasilek backdoor in VMware Tools during a two-year medical-organization intrusion.
- · 2d agoPartisan Zmiy Malware Campaign Uses Telegram and DNS Tunneling to Target Healthcare Networks
GBHackers· 62
Cyber Partisans maintained roughly two-year espionage access to a medical organization using an updated Vasilek Telegram-controlled backdoor, GOST tunnels, and DNS tunneling.