Cyber & AI intelligence
Wasteland.
Briefs indexed3104
Issues31
Published Mondays07:30 CT
▣ Breach MOSCOW-HEALTHCARE- 2026-10-09

Moscow Department of Health: Belarusian Cyber Partisans Claim 2023 Network Breach

"The Belarusian Cyber Partisans hacktivist group has publicly said it breached the Moscow Department of Health in 2023. The group says it got administrator-level access to the department's infrastructure, including…"

The Belarusian Cyber Partisans hacktivist group has publicly said it breached the Moscow Department of Health in 2023. The group says it got administrator-level access to the department's infrastructure, including systems connected to other government agencies, according to a statement given to Recorded Future News on October 9, 2026 (The Record). The claim follows a report published the previous week by Solar, the cybersecurity subsidiary of state-controlled Rostelecom. Solar named the group as the likely perpetrator of a long-running intrusion at an unnamed Russian healthcare organization. Neither the victim nor any Russian regulator or national CERT has issued a statement. No primary-tier source exists for this incident, and nobody has published a record count. The two main accounts also disagree on when the intrusion began and how long it lasted.

What Happened

There are two separate accounts, and they do not line up neatly.

The group's account. The Cyber Partisans told Recorded Future News that they got into the Moscow Department of Health in 2023, reached "full access to its entire infrastructure relatively quickly and with little effort," spent months inside, and then walked away. "The network was not a priority for us, so we did not maintain our access," the group said (The Record). A group representative also claimed it currently has access to hundreds of IT systems across Russia and Belarus. The Record could not verify that claim.

Solar's account. Solar says it discovered the compromise in December 2025 and traced the earliest signs of intrusion to early 2024. That suggests the attackers may have been present for nearly two years (The Record; Threadlinqs; CyberWorldOps). Cyberpress, summarizing Solar's 4RAYS team, reports that the investigation began after a subsidiary medical organization scanned the customer's domain. That scan turned up numerous antivirus alerts, including detections for the Vasilek backdoor and the GOST tunneling tool. Solar did not name the victim. It described the organization only as a healthcare entity with extensive infrastructure linked to many other healthcare institutions.

Where accounts differ: - Start date: The group says 2023. Solar's earliest evidence is from early 2024. - End date: The group says it abandoned access after reaching its objectives. Solar's findings point to activity continuing until discovery in December 2025. - Victim identity: The group names the Moscow Department of Health. Solar's report does not name the victim. The Record frames the group's statement as confirming involvement in the intrusion Solar disclosed, but no source independently confirms that Solar's victim and the Moscow Department of Health are the same organization.

Possible explanations include a gap in Solar's log retention, a second actor or a later re-entry, or the group misremembering or misstating its timeline. None of the sources settles which is true. CyberWorldOps also notes that Solar's timeline, malware analysis and attribution have not been independently verified.

On background, The Clarity reports that Russia's Supreme Court designated the group an extremist organization in July 2026, the first time Russia has applied that label to a hacking group. The Clarity is the only provided source that reports this.

What Was Taken

No source gives a record count, a data volume or a list of exfiltrated datasets.

Treat the scope of data exposure as unknown. Solar's description of "sensitive medical information" is the most authoritative statement available.

Why It Matters

Note: The FELG status page included in the source set covers a separate Polish healthcare software incident (September to October 2026) and is unrelated to this breach.

The Attack Technique

No source discloses how the attackers first got in. The following comes from Solar's analysis as reported by secondary outlets and has not been independently verified.

What Organizations Should Do

  1. Hunt for Telegram and DNS-based command and control. Flag servers making connections to Telegram API endpoints, and baseline DNS query volume and entropy to catch tunneling tools such as DNSCat2. Domain controllers and management servers should almost never talk to Telegram.
  2. Audit services against known-good baselines. Look for services whose names imitate VMware, Windows Update/WSUS or "Insider" components but whose binaries are unsigned, recently modified or stored in unusual paths. Check the integrity of vmtools.dll and anything unexpected in VMware Tools directories.
  3. Remove or monitor dormant software. Unused agents and tools (VMware Tools on hosts that no longer need it, legacy management clients) give attackers places to hide. Uninstall them, or put them under file-integrity monitoring.
  4. Look for activity that runs on a schedule. Correlate outbound connections by time of day and day of week. A tunnel that comes up for one hour every Saturday night is easy to miss in a daily review but stands out in a weekly one.
  5. Restrict trusted-relationship paths. Hub organizations should segment connections to subsidiary and partner institutions, enforce least privilege on cross-organization accounts, and log administrative access that crosses those boundaries. Connected organizations should treat traffic from the hub as untrusted until it is verified.
  6. Scope investigations past the first artifact. Keep logs long enough to cover realistic dwell times (24 months or more for critical infrastructure). Treat attacker or third-party claims of an earlier entry date as leads to investigate, not as noise.

Sources: Belarusian hacktivists admit to 2023 breach of Russian state health... | Belarusian hackers claim 2023 hack of Moscow health network | Belarusian hacktivists admit to 2023 breach of Russian state health... | Belarusian Cyber Partisans maintain two-year Threadlinqs | Vasilek Backdoor Breach: Russian Healthcare Network Hacked | Partisan Zmiy Hackers Use Telegram-Controlled Vasilek Backdoor to S... | Incydent FELG — FELG | Поставка сертификатов на… — тендер №0173200001426001677