Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
The Belarusian Cyber Partisans have confirmed they breached the Moscow Department of Health in 2023, claiming an operation that a Russian security firm had partially attributed to them without naming the target. The statement, given to The Record by Recorded Future News on October 9, 2026, comes five days after Solar — a subsidiary of the state telecom giant Rostelecom — published a report describing a nearly two-year intrusion into a Russian healthcare organization. The group corrected the timeline, moving the start of access one year earlier than Solar reported.
- The Cyber Partisans claim they infiltrated the Moscow Department of Health in 2023, gaining administrator-level access to the entire infrastructure
- Solar discovered the intrusion in December 2025 with traces dating to early 2024, estimating nearly two years of persistence
- The Vasilek malware version 1.5.8 ensured persistence via Windows services and compromise of the VMware Tools vmtools.dll library
- Russia's Supreme Court designated the Cyber Partisans an "extremist organization" in July 2026, three months before their claim
The Timeline Gap as Narrative Battleground
The operation stands out for a discrepancy that goes beyond mere chronology. Solar reported discovering the intrusion in December 2025, with traces dating to early 2024 — a timeline implying nearly two years of persistence. The Cyber Partisans implicitly dispute this reconstruction, stating they operated in 2023 and spent "months" in the network before abandoning it.
The group justified the abandonment with a priority assessment: "The network was not a priority for us, so we did not maintain our access". The statement, quoted by The Record, introduces a rare element in hacktivist claims: an admission they considered the target secondary. This contrasts with Solar's hypothesis that the absence of destructive activity was linked to the access value for "further espionage operations and trust-relationship-based attacks."
The divergence between the two versions — 2023 versus 2024 as the start year, months versus nearly two years of duration — cannot be resolved with available data. None of the dossier sources provide independent technical elements (sample hashes, IoCs, CVEs) capable of precisely dating the intrusion.
How the Vasilek Backdoor Worked in the Healthcare System
Solar's report identified the Vasilek malware as the operation's central tool. It is a Windows backdoor that communicates via the Telegram Bot API, a choice that exploits the legitimacy of traffic to messaging servers to camouflage command-and-control communications. Solar specified version 1.5.8, previously documented by Kaspersky.
Persistence operated on two levels: standard Windows services and replacement of the vmtools.dll library associated with VMware Tools. This second technique is particularly relevant for the virtualized infrastructure typical of large healthcare organizations, where compromising legitimate hypervisor management components guarantees cross-visibility across multiple virtual machines without requiring anomalous software installations.
To bypass Telegram restrictions in Russia, the attackers employed DNS tunnels and proxy chains. These alternative communication methods, documented by Solar and the Mallory threat intelligence platform, indicate careful design for C2 channel resilience in environments with restrictive traffic controls.
Why Claim Now: A Controlled Attribution Strategy
The timing of the claim is not accidental. On October 5, 2026, Solar published its report; on October 9, the Cyber Partisans responded by confirming the specific target and correcting the timeline. This pattern — claiming after exposure by an adversary — inverts the classic hacktivism cycle, where the group announces first and intelligence reactively verifies later.
The choice has implications for attribution credibility. On one hand, confirming the Moscow Department of Health as the specific target provides a detail Solar had omitted, protecting the organization's identity with the generic label "Russian healthcare organization." On the other, correcting the timeline to favor an earlier start serves to maximize the perception of the group's competence, but is not independently verifiable.
The geopolitical context adds complexity. Solar is a subsidiary of Rostelecom, a state-controlled Russian telecom company. Its report, while containing specific technical details, is potentially influenced by national intelligence interests. The Cyber Partisans were designated an "extremist organization" by Russia's Supreme Court in July 2026, a classification that makes any activity punishable by criminal proceedings and that may have accelerated the decision to claim publicly.
Why It Matters
The dossier does not specify remedial measures or operational recommendations from Solar or the Cyber Partisans. The source does not document the initial access method, the quantity or type of data actually exfiltrated, nor independently verify the claim of "access to hundreds of systems" in Russia and Belarus.
The brief lists no specific defensive actions: no indication emerges regarding patches to apply, controls to enable, or configurations to modify. The compromise of vmtools.dll and communication via Telegram Bot API, while documented as employed techniques, are not accompanied by verifiable indicators of compromise or monitoring thresholds.
What the dossier makes evident is the limit of threat attribution intelligence in open conflict contexts. The absence of independent technical data — CVEs, hashes, IoCs — prevents establishing which timeline is correct. Solar has access to the crime scene but state interests; the Cyber Partisans have an incentive to exaggerate scope but provide details the official report omits.
"We gained full access to its entire infrastructure relatively quickly and with little effort" — Belarusian Cyber Partisans, statement to Recorded Future News
Medical Data and Military Intelligence: A Blurred Line
The Cyber Partisans stated that the medical information obtained "could help assess Russian military losses in Ukraine." This assertion, reported by The Record, expands the healthcare sector's threat surface beyond classic personal data exfiltration: medical records become a proxy for casualty estimates, accessible through correlations between military units and treatment facilities.
The claim remains declaratory. The dossier does not document that the data was actually used for this purpose, nor that correlation analyses between health records and combat losses were conducted. Solar reported that the attackers did not destroy data or disrupt operations, a finding that — while technically neutral — fuels the hypothesis of an intelligence operation rather than sabotage.
The declared use of health data for military purposes also raises an ethical and legal question on hacktivist operations: the Cyber Partisans' anti-regime motivation overlaps with potential intelligence applications that cross the line between digital protest and wartime espionage.
FAQ
Why did the Cyber Partisans wait three years to claim the breach?
The group responded to a Solar report from October 5, 2026 that had partially attributed the intrusion to them without identifying the target. The late claim serves to correct the timeline and reclaim ownership of the operation after adversarial exposure.
What is the difference between Solar's version and the Cyber Partisans' version?
Solar places the intrusion start in early 2024 with discovery in December 2025, estimating nearly two years of persistence. The Cyber Partisans claim they operated in 2023 for "months," voluntarily abandoning access due to low priority.
Is Solar's report reliable?
Solar is a subsidiary of Rostelecom, a state-owned Russian telecom company. The report contains specific technical details but its potentially interested nature warrants caution in evaluation. No independent source has corroborated the attribution or technical data.
Sources
- https://therecord.media/belarusian-cyber-partisans-claim-2023-russia-healthcare-hack
- https://www.byteseu.com/2437647/
- https://www.byteseu.com/2427003/
- https://mallory.ai/stories/01a10ca4-3da4-74d7-a3f6-88c5c92fb51f
- https://www.cysecurity.news/2026/10/belarusian-hackers-compromised-russian.html
- https://therecord.media/belarusian-hacktivists-two-years-Russian-healthcare-network
- https://therecord.media/cyberattack-aeroflot-russia-delays
- https://therecord.media/russia-seeks-extremist-label-for-hacker-groups
Information verified against cited sources and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.