Russian cybersecurity firm Solar, a subsidiary of state-controlled Rostelecom, said it discovered in December 2025 an intrusion into a Russian healthcare organisation traced back to early 2024 — nearly two years of access — and attributed it to the Belarusian Cyber Partisans. The targeted healthcare organisation was not named but operates infrastructure with connections to numerous other healthcare providers, giving the attackers opportunities to pivot into trusted-relationship targets. Solar said the hackers accessed sensitive medical data but did not disrupt or destroy systems, a restraint the researchers linked to preserving the access for espionage and trusted-relationship attacks. The intrusion used Vasilek, a Windows backdoor first documented by Kaspersky in 2025 that communicates with its operators over Telegram, collects system information and can execute commands, transfer files, capture screenshots and record keystrokes; Solar's copy was a newer variant. Why it matters: a two-year, deliberately quiet presence inside another state's healthcare estate illustrates how state-adjacent actors trade destructive impact for espionage persistence, and how healthcare networks — and their trusted interconnections — remain a preferred residency for long-dwell access.
| Attribute | Detail |
|---|---|
| Sector | Healthcare |
| Date | 2026-10-06 |
| Source | The Record |
| Reliability | Tier 2 |