A prolonged Partisan Zmiy intrusion into a medical organization, exposing an updated malware toolkit that combined Telegram command channels, DNS tunneling, and scheduled payload execution.
Investigators joined the response in December 2025 and traced the earliest evidence of compromise to early 2024, indicating approximately two years of access without observed destructive activity.
The organization maintained extensive infrastructure and bidirectional trust relationships with subsidiary medical institutions.
Researchers assess that preserving these connections may have offered greater value for espionage and subsequent attacks than immediate disruption.
Attribution rested on Vasilek malware, overlapping command infrastructure, and established tactics associated with Cyber Partisans.
The investigation began after scanning activity originated from a subsidiary medical organization.
Historical antivirus detections identified Vasilek and GOST, while early command execution artifacts matched Impacket’s wmiexec.py: command output redirected through the localhost ADMIN$ share into timestamped files.
Attackers maintained persistence through Windows services and malicious DLLs masquerading as system components.
Service creation records remained in Windows System logs under Event ID 7045. Because operators repeatedly replaced payloads at identical paths, filenames alone could not reliably identify which tool had occupied each location.
A previously undescribed loader, authd.exe, ran as the “VMware Auth Adapter” service inside the legitimate VMware Tools directory.
It orchestrated GOST and Vasilek payloads concealed as vmtoolsd32.exe, rpctool32.exe, and WsusService.exe.
The Solar 4RAYS team encountered another attack, by Partisan Zmiy (the Cyber Partisans group is designated as extremist and its activities are banned in Russia), this time targeting a medical organization.
The scheduler activated one GOST tunnel every Saturday between 22:00 and 23:00. Two additional payloads launched once, eight hours after service startup.
While analyzing the malicious activity, we discovered modifications to the registry key tags of the legitimate
AppMgmt service.
Researchers interpreted the restricted window as a likely backup channel and the delayed execution as an effort to separate malicious traffic from startup activity.
Shortly before discovery, operators replaced VMware’s signed vmtools.dll with an unsigned Vasilek library, retaining the original as vmtoolsd.dll.
The software directory was legitimate but operationally neglected, providing an effective concealment location.
Vasilek version 1.5.8 is a 32-bit Windows backdoor controlled through Telegram group messages.
Its command table contains 59 entries, including aliases, supporting shell execution, file transfers, screenshots, keylogging, clipboard collection, and process management.
Operators retrieved commands through getUpdates long polling and returned results using Telegram’s Bot API.
Group-based anonymous posting concealed the sender’s account, while task identifiers helped operators associate responses with individual commands.
Before execution, Vasilek compared a salted SHA-256 hostname hash against a hardcoded value, restricting operation to the intended machine.
OLLVM-based control-flow flattening, encrypted strings, and dynamically resolved APIs further complicated analysis.
Kaspersky ICS CERT’s June 2025 research previously documented Vasilek’s Telegram control architecture and hostname-dependent execution, establishing the technical baseline for this updated investigation.
Telegram was only one access route. DNSCat2, PartisanDNS, and a GOST–3proxy chain provided alternative connectivity, preventing disruption of one channel from automatically removing access.
Observed domains included c0ce[.]org, p7cp[.]org, w3a01[.]net, f91j[.]org, and the reused gov-by[.]com. These indicators overlapped with, or closely resembled, infrastructure documented in earlier Cyber Partisans research.
Investigators also found evidence suggesting temporary modification and restoration of the legitimate AppMgmt service.
Public tools such as NimExec support comparable service-path manipulation, although their availability does not establish their use in this incident.
The case underscores the importance of investigating recurring detections, auditing service changes, verifying signatures in trusted software directories, and correlating suspicious DNS traffic with unexpected messenger API connections across interconnected healthcare environments.
| Hash type | Hash value |
|---|---|
| MD5 | a6af32b1381d8985049e2d5ec1889bd9 |
| MD5 | 338f7eafdfe45e93e57889ebd064d0d5 |
| MD5 | 39e64553b7ddf579240e6642042e6840 |
| MD5 | a6ce67f063fce60954bb6cea4c969aac |
| MD5 | 1199d2f2b1a58435113555b02172bc79 |
| SHA1 | bdeac4b8e9a3c48661adf0c2ee5f05b58cee76eb |
| SHA1 | ed999aaaf1d032c76a51f4aececb99d06c371b33 |
| SHA1 | cd61f92873625dd25a31f414617347d1fa132747 |
| SHA1 | 56df605a33fb77c91bdb92033efe983f336deb23 |
| SHA1 | efe3503bd021de67e884878c6de1e8b110ed2ee7 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…