Belarusian hacktivists tied to Russian healthcare network intrusion
Solar and the Belarusian Cyber Partisans describe a multi-year Russian healthcare intrusion that accessed medical data without disruption.
Russian security firm Solar, a Rostelecom subsidiary, said it discovered in December 2025 an intrusion at a Russian healthcare organization that it traces to early 2024 and attributes to the Belarusian Cyber Partisans. The group separately said it infiltrated Moscow’s Department of Health in 2023, quickly obtained administrator-level access to infrastructure linked to other government agencies, and later stopped maintaining that access—a start date and victim identity that differ from Solar’s account of an unidentified organization and activity beginning in early 2024. Both accounts say sensitive medical information was accessed but not destroyed and that operations were not disrupted; Solar believed the access was kept for espionage and trusted-relationship attacks on connected healthcare organizations. Researchers said the intruders used a newer version of the Vasilek Windows backdoor, which communicates over Telegram and supports command execution, file transfers, screenshots, and keylogging. The group said the data could help assess Russian military casualties in Ukraine and claimed unverified access to hundreds of systems in Russia and Belarus. Russia’s Supreme Court designated the Cyber Partisans an extremist organization in July.
- Solar, a Rostelecom subsidiary, said it discovered in December 2025 a healthcare intrusion it traces to early 2024 at an unidentified Russian organization and attributes to the Belarusian Cyber Partisans.
- The Cyber Partisans say they entered Moscow’s Department of Health in 2023, quickly gained administrator-level access to infrastructure linked to other government agencies, and later stopped maintaining that access.
- Sources disagree on timing and victim: the group cites a 2023 Moscow health-department breach it later abandoned, while Solar describes related activity from early 2024 at an unnamed provider found in December 2025.
- Sensitive medical data was accessed; reports say data was not destroyed and operations were not disrupted.
- Solar assessed the quiet access as intended for espionage and trusted-relationship attacks against connected healthcare organizations.
- Researchers said a newer Vasilek Windows backdoor used Telegram for command-and-control and supported command execution, file transfers, screenshots, and keylogging.
- The group told Recorded Future News the data could help assess Russian military casualties in Ukraine and claimed unverified access to hundreds of systems in Russia and Belarus.
- Russia’s Supreme Court designated the Cyber Partisans an extremist organization in July.
Coverage timelineoldest first · each row is one article
- · 4d agoBelarusian hacktivists spent two years inside Russian healthcare network, researchers say
The Record· 60
Belarusian Cyber Partisans maintained nearly two years of access to a Russian healthcare network, reading sensitive medical data, researchers say.
- · 8h agoBelarusian hacktivists admit to 2023 breach of Russian state healthcare network
The Record· 58
Belarusian Cyber Partisans say they breached Moscow’s health department in 2023 and accessed medical systems.