DEV Community

Anoymask
Anoymask

Posted on

Partisan Zmiy: Nearly Two Years of Access to a Healthcare Network

1. Overview

  • Article: Partisan Zmiy: снова на радаре
  • Source: Solar 4RAYS
  • Published Date: October 2, 2026
  • Updated Date: Unknown (not specified in the primary source)
  • Report Revision Reason: Technical review: clarified the investigation period, separate schedules for the custom loader and payloads, distinction between features and observed execution, 59 items including aliases, and a discrepancy in the vmtools.dll payload name within the documentation.
  • Original: Partisan Zmiy: снова на радаре
  • Related Sources: The Record
  • Related Malware, Threat Groups, CVEs, Products: Vasilek, PartisanDNS, DNSCat2, GOST, 3proxy, Belarusian Cyber Partisans, Partisan Zmiy, Windows, Telegram Bot API, VMware Tools
  • Severity: Critical (lurked in a healthcare network for about two years, appeared to reach core environments including domain controllers, and accessed sensitive medical data. Lateral movement to trusted related organizations has been suggested as a possibility, but actual compromise remains unconfirmed.)

2. Quick Summary

An attacker tracked by Solar 4RAYS as Partisan Zmiy maintained access to a healthcare network for approximately two years. The operation involved Vasilek, RDP/SMB, Telegram C2, and separate DNS tunneling channels, and included access to core systems and sensitive medical data.

3. Attack Flow

Long-Term Persistence and Remote Control in a Healthcare Network

  1. The initial access vector is undetermined. The earliest activity trace in the target environment dates back to early 2024, and a residency period of approximately two years was reported until Solar began its investigation in December 2025. October 2026 is the report publication date.
  2. The attacker moved laterally using Impacket wmiexec, ADMIN$, and legitimate RDP/SMB, appearing to reach core systems including domain controllers.
  3. Access was maintained using Windows services, a custom scheduled loader, and replacement of vmtools.dll. Saturday night windows were configured for GOST, while Vasilek and another GOST instance were set to run once eight hours after the service started.
  4. In addition to Vasilek's Telegram Bot API communication, alternative communication paths were maintained using DNSCat2/PartisanDNS or GOST plus 3proxy. Screen capture, keylogging, and file transfer are features of Vasilek, but the execution of all features was not confirmed in this incident.
  5. While sensitive medical data was accessed, neither destructive operations nor successful compromise of related organizations were confirmed.

4. Attacker Positioning and Execution Location

  • Located on Windows hosts after initial access and within the internal network reachable via legitimate RDP/SMB.
  • C2 infrastructure is placed on external channels such as Telegram, proxies, and DNS tunnels.

5. Visibility for Victims and Administrators

Victims

  • Healthcare services continued and no destructive behavior was confirmed, making the compromise potentially difficult for users to notice.

Administrators

  • Indicators include new services, custom loader execution settings, replaced vmtools.dll files, ADMIN$, RDP, the Telegram API, DGA/DNS tunneling, and nighttime activity.

6. Conditions for Success and Failure

Success Conditions

  • Code execution and credential usage become possible on the initial Windows host.
  • Internal systems are reached via RDP/SMB and trust relationships.
  • External C2 communication is established via Telegram, proxies, or DNS tunneling.

Failure Conditions and Risk Reduction

  • Restrict administrative RDP/SMB to jump hosts, enforce MFA, and apply tiering.
  • Monitor signatures and hashes of VMware Tools and service binaries, avoiding allowlists based solely on paths.
  • Restrict the Telegram Bot API and abnormal DNS queries from the healthcare server segment.

7. Impact of Successful Attacks

  • Long-term network access and access to sensitive medical data. Whether medical data was exfiltrated remains unconfirmed.
  • Access to core systems, including domain controllers, and a risk of lateral movement to related organizations. Successful compromise of those organizations remains unconfirmed.
  • Potential collection of additional information through Vasilek's screenshot, keylogging, clipboard collection, and file transfer capabilities. Use of all these capabilities in this incident has not been confirmed.

8. Observable Logs

  • Email: No reports indicate email was used for initial access.
  • Proxy / SWG / DNS: Check for the Telegram Bot API, unknown HTTPS proxies, DGA domains, and long or high-entropy DNS queries.
  • Endpoint / EDR: Check system Event ID 7045, custom loader settings and child processes, vmtools.dll hashes, Vasilek, wmiexec output files, and keylogger/screenshot files.
  • Identity / IdP: Check for nighttime RDP, service accounts, domain admins, cross-trust authentication, and unusual logon types.
  • SaaS / Cloud: Relevant SaaS/cloud audit logs are used to verify related authentication, setting changes, and external API usage.
  • Network: Check for SMB ADMIN$, RDP lateral movement, DNSCat2-type traffic, and GOST/3proxy.

9. Determining Attack Success

  • Confirmed Information Theft or Session Compromise: Public information: Solar reported access to sensitive medical data and presented fragments of Telegram command responses and transmission of a GOST configuration file. Whether medical data was exfiltrated, and the scope of any such exfiltration, remain unconfirmed. Assessment criteria: Distinguish data access from external transmission and correlate the relevant files with transfer records.
  • Confirmed Subsequent Compromise: A residency period of about two years, internal lateral movement, Vasilek persistence, and remote command capabilities were confirmed. Successful compromise of related organizations remains unconfirmed.

10. Investigation Playbook

  • Investigation Starting Point: Event ID 7045, unknown VMware Tools DLLs, Impacket artifacts, and Telegram/DNS tunneling.
  • Initial Verification: Review host timelines, accounts, services, custom loaders, trusts, RDP/SMB, and egress traffic against the period from early 2024 to the start of the investigation in December 2025, along with surrounding retention ranges.
  • Endpoint and Server Investigation: Preserve memory, service binaries, vmtools.dll, prefetch data, Amcache, SRUM, and custom loader settings/child processes. Published schedules do not imply Windows Task Scheduler registration.
  • Authentication and Cloud Investigation: Check domain controller logs, 4624/4672 events, RDP, service accounts, and cross-trust authentication.
  • Tracking Subsequent Activity: Track medical data access, archiving, exfiltration, connections to related organizations, and C2 commands.
  • Containment: Block C2, isolate infected hosts, rotate privileged credentials, restrict trusts, and perform clean rebuilds.
  • Decision Categories: Separate initial access, lateral movement, persistence, C2, data access, exfiltration, and compromise of related organizations.

11. Defense and Detection Ideas

  • Single Events: Detect unknown services paired with VMware Tools names, mismatched vmtools.dll files, and wmiexec artifacts.
  • Time-Series Correlation: Correlate nighttime RDP/SMB, service creation, Telegram/DNS tunneling, and file access.
  • Threat Hunting: Search across trusted domains for Vasilek artifacts, DGA domains, GOST/3proxy, timestomping, and evidence of payload replacement at the same file paths.
  • Log Limitations: Long-term residency causes older logs to be missing, and legitimate RDP/SMB blend with benign activity.
  • Priority Mitigations: Prioritize administrative path separation, MFA, long-term log retention, egress control, and service/DLL integrity monitoring.

12. Facts, Inferences, and Hypotheses

Facts

  • Solar 4RAYS initiated an investigation in December 2025, reporting a residency period of about two years starting from early 2024 in the target environment and access to sensitive medical data. This does not indicate that the compromise continued from the start of the investigation until the publication in October 2026.
  • The attacker established persistence through Windows services, a custom loader, and replacement of the legitimate vmtools.dll in the VMware Tools directory with a malicious DLL. RDP/SMB and Impacket wmiexec were also used. Solar's report identifies the replacement DLL's payload as Vasilek in the main text and PartisanDNS in the IOC appendix; this discrepancy remains unresolved.
  • The Vasilek 1.5.8 command table contains 59 entries, including shorthand aliases, covering command execution, process creation, file upload and download, screenshots, keylogging, clipboard collection, attempts to restart with elevated privileges via runas, and self-deletion.
  • C2 relies primarily on the Telegram Bot API, while also utilizing HTTPS proxies, DNSCat2/PartisanDNS, GOST, and 3proxy.
  • Solar 4RAYS attributes the activity to Cyber Partisans/Partisan Zmiy based on infrastructure and TTPs. No destructive behavior was confirmed.

Inferences

  • Long-term lurking, nighttime schedules for some payloads, masquerading, and timestomping suggest that information gathering and access maintenance were prioritized over availability disruption.

Hypotheses

  • Access may have been preserved as an entry path to related healthcare organizations sharing two-way trusts with the parent organization, though actual compromise of related organizations remains unconfirmed.

13. MITRE ATT&CK Mapping

ID Technique Confidence Basis
T1021.001 Remote Services: Remote Desktop Protocol high Lateral movement was conducted using legitimate RDP.
T1021.002 Remote Services: SMB/Windows Admin Shares high SMB and ADMIN$ were utilized.
T1102.002 Web Service: Bidirectional Communication high The Telegram Bot API was used for bidirectional C2 communication.
T1056.001 Input Capture: Keylogging high Mapping based on Vasilek having keylogger capabilities. This does not imply execution of all features in this incident.

14. Unknowns and Additional Investigation

  • Exact methods and timing of initial access.
  • Whether medical data was exfiltrated, and the full scope of the data accessed or, if confirmed, exfiltrated.
  • Whether lateral movement to trusted related organizations actually occurred.
  • All commands executed by the attacker and the complete C2 infrastructure over the two-year period.
  • The reason for the payload name discrepancy for the replaced vmtools.dll between Vasilek in the body and PartisanDNS in the IOC appendix.

15. Impact on SOCs and Organizations

In healthcare environments, RDP, SMB, domain trusts, and VMware Tools overlap with legitimate operations. Correlate long-term time series for service names alongside binary paths, signatures, hashes, vmtools.dll integrity, Event ID 7045, SMBServer/Security 1015 events, nighttime schedules for certain payloads, and Telegram/DNS tunneling.

16. Summary by Audience

  • For SOCs: Correlate service creations, VMware Tools DLLs, Impacket artifacts, RDP/SMB, and Telegram/DNS tunneling over long timeframes.
  • For Administrators: Audit trust relationships and administrative shares, separate administrative paths, enforce MFA, apply egress controls, and verify VMware Tools integrity.
  • For Users: Report suspicious connections and device anomalies, and avoid using personal services on terminals handling medical data.

Top comments (0)