Cyber Security News

Partisan Zmiy Malware Campaign Uses Telegram and DNS Tunneling to Target Healthcare Networks

A prolonged Partisan Zmiy intrusion into a medical organization, exposing an updated malware toolkit that combined Telegram command channels, DNS tunneling, and scheduled payload execution.

Investigators joined the response in December 2025 and traced the earliest evidence of compromise to early 2024, indicating approximately two years of access without observed destructive activity.

The organization maintained extensive infrastructure and bidirectional trust relationships with subsidiary medical institutions.

Researchers assess that preserving these connections may have offered greater value for espionage and subsequent attacks than immediate disruption.

Attribution rested on Vasilek malware, overlapping command infrastructure, and established tactics associated with Cyber Partisans.

The investigation began after scanning activity originated from a subsidiary medical organization.

Historical antivirus detections identified Vasilek and GOST, while early command execution artifacts matched Impacket’s wmiexec.py: command output redirected through the localhost ADMIN$ share into timestamped files.

Attackers maintained persistence through Windows services and malicious DLLs masquerading as system components.

Service creation records remained in Windows System logs under Event ID 7045. Because operators repeatedly replaced payloads at identical paths, filenames alone could not reliably identify which tool had occupied each location.

A previously undescribed loader, authd.exe, ran as the “VMware Auth Adapter” service inside the legitimate VMware Tools directory.

It orchestrated GOST and Vasilek payloads concealed as vmtoolsd32.exe, rpctool32.exe, and WsusService.exe.

The Solar 4RAYS team encountered another attack, by Partisan Zmiy (the Cyber ​​Partisans group is designated as extremist and its activities are banned in Russia), this time targeting a medical organization. 

Partisan Zmiy Malware

The scheduler activated one GOST tunnel every Saturday between 22:00 and 23:00. Two additional payloads launched once, eight hours after service startup.

While analyzing the malicious activity, we discovered modifications to the registry key tags of the legitimate
AppMgmt service.

Timestamps of malicious services (Source : Solar 4RAYS).

Researchers interpreted the restricted window as a likely backup channel and the delayed execution as an effort to separate malicious traffic from startup activity.

Shortly before discovery, operators replaced VMware’s signed vmtools.dll with an unsigned Vasilek library, retaining the original as vmtoolsd.dll.

The software directory was legitimate but operationally neglected, providing an effective concealment location.

Vasilek version 1.5.8 is a 32-bit Windows backdoor controlled through Telegram group messages.

Its command table contains 59 entries, including aliases, supporting shell execution, file transfers, screenshots, keylogging, clipboard collection, and process management.

Key pointer(Source : Solar 4RAYS).

Operators retrieved commands through getUpdates long polling and returned results using Telegram’s Bot API.

Group-based anonymous posting concealed the sender’s account, while task identifiers helped operators associate responses with individual commands.

Before execution, Vasilek compared a salted SHA-256 hostname hash against a hardcoded value, restricting operation to the intended machine.

OLLVM-based control-flow flattening, encrypted strings, and dynamically resolved APIs further complicated analysis.

Kaspersky ICS CERT’s June 2025 research previously documented Vasilek’s Telegram control architecture and hostname-dependent execution, establishing the technical baseline for this updated investigation.

Telegram was only one access route. DNSCat2, PartisanDNS, and a GOST–3proxy chain provided alternative connectivity, preventing disruption of one channel from automatically removing access.

Observed domains included c0ce[.]org, p7cp[.]org, w3a01[.]net, f91j[.]org, and the reused gov-by[.]com. These indicators overlapped with, or closely resembled, infrastructure documented in earlier Cyber Partisans research.

Investigators also found evidence suggesting temporary modification and restoration of the legitimate AppMgmt service.

Public tools such as NimExec support comparable service-path manipulation, although their availability does not establish their use in this incident.

The case underscores the importance of investigating recurring detections, auditing service changes, verifying signatures in trusted software directories, and correlating suspicious DNS traffic with unexpected messenger API connections across interconnected healthcare environments.

IOCs

Hash typeHash value
MD5a6af32b1381d8985049e2d5ec1889bd9
MD5338f7eafdfe45e93e57889ebd064d0d5
MD539e64553b7ddf579240e6642042e6840
MD5a6ce67f063fce60954bb6cea4c969aac
MD51199d2f2b1a58435113555b02172bc79
SHA1bdeac4b8e9a3c48661adf0c2ee5f05b58cee76eb
SHA1ed999aaaf1d032c76a51f4aececb99d06c371b33
SHA1cd61f92873625dd25a31f414617347d1fa132747
SHA156df605a33fb77c91bdb92033efe983f336deb23
SHA1efe3503bd021de67e884878c6de1e8b110ed2ee7

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Mayura Kathir

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago