The Belarusian Cyber Partisans hacktivist group has publicly said it breached the Moscow Department of Health in 2023. The group says it got administrator-level access to the department's infrastructure, including systems connected to other government agencies, according to a statement given to Recorded Future News on October 9, 2026 (The Record). The claim follows a report published the previous week by Solar, the cybersecurity subsidiary of state-controlled Rostelecom. Solar named the group as the likely perpetrator of a long-running intrusion at an unnamed Russian healthcare organization. Neither the victim nor any Russian regulator or national CERT has issued a statement. No primary-tier source exists for this incident, and nobody has published a record count. The two main accounts also disagree on when the intrusion began and how long it lasted.
What Happened
There are two separate accounts, and they do not line up neatly.
The group's account. The Cyber Partisans told Recorded Future News that they got into the Moscow Department of Health in 2023, reached "full access to its entire infrastructure relatively quickly and with little effort," spent months inside, and then walked away. "The network was not a priority for us, so we did not maintain our access," the group said (The Record). A group representative also claimed it currently has access to hundreds of IT systems across Russia and Belarus. The Record could not verify that claim.
Solar's account. Solar says it discovered the compromise in December 2025 and traced the earliest signs of intrusion to early 2024. That suggests the attackers may have been present for nearly two years (The Record; Threadlinqs; CyberWorldOps). Cyberpress, summarizing Solar's 4RAYS team, reports that the investigation began after a subsidiary medical organization scanned the customer's domain. That scan turned up numerous antivirus alerts, including detections for the Vasilek backdoor and the GOST tunneling tool. Solar did not name the victim. It described the organization only as a healthcare entity with extensive infrastructure linked to many other healthcare institutions.
Where accounts differ: - Start date: The group says 2023. Solar's earliest evidence is from early 2024. - End date: The group says it abandoned access after reaching its objectives. Solar's findings point to activity continuing until discovery in December 2025. - Victim identity: The group names the Moscow Department of Health. Solar's report does not name the victim. The Record frames the group's statement as confirming involvement in the intrusion Solar disclosed, but no source independently confirms that Solar's victim and the Moscow Department of Health are the same organization.
Possible explanations include a gap in Solar's log retention, a second actor or a later re-entry, or the group misremembering or misstating its timeline. None of the sources settles which is true. CyberWorldOps also notes that Solar's timeline, malware analysis and attribution have not been independently verified.
On background, The Clarity reports that Russia's Supreme Court designated the group an extremist organization in July 2026, the first time Russia has applied that label to a hacking group. The Clarity is the only provided source that reports this.
What Was Taken
No source gives a record count, a data volume or a list of exfiltrated datasets.
- Solar says the attackers accessed sensitive medical information but did not destroy data or disrupt operations (The Record; CyberWorldOps).
- Cyberpress, relaying Solar, reports that the attackers reached domain controllers and centralized management systems.
- ZeroHour, summarizing The Record's full article, reports that the group said the data could help assess Russian military casualties in Ukraine. If accurate, that suggests a focus on patient and treatment records with intelligence value rather than bulk theft for profit.
- The group's claim of access to systems connected to other government agencies has not been independently verified.
Treat the scope of data exposure as unknown. Solar's description of "sensitive medical information" is the most authoritative statement available.
Why It Matters
- Hacktivists operating like an espionage team. Threadlinqs classifies the activity as espionage-motivated. Long dwell time, deliberately limited operating windows and no destructive payload look more like a state-aligned intelligence operation than typical hacktivist defacement or wiper activity.
- Hub organizations multiply exposure. Solar specifically flagged the risk of trusted-relationship attacks, because the victim connects to many other healthcare institutions. CyberWorldOps notes that the available reporting does not show the attackers actually pivoted into any connected entity. Under either timeline, though, administrator-level control of a hub network puts its connected organizations at risk.
- Medical data as military intelligence. If the casualty-assessment motive is accurate, civilian health systems in countries at war are collection targets, not just ransomware targets.
- Scoping depends on the start date. As The Clarity points out, an investigation that starts from Solar's early-2024 evidence would miss the year in which the group says it got in. Incident responders anywhere should not treat the first detected artifact as the true start of an intrusion.
- Context, not causation: A Moscow public procurement notice (Kpshka/EIS) dated September 11, 2026 shows a tender worth about ₽130M for technical support of anti-unauthorized-access security software across Moscow's state healthcare organizations. Nothing in the sources links this tender to the breach.
Note: The FELG status page included in the source set covers a separate Polish healthcare software incident (September to October 2026) and is unrelated to this breach.
The Attack Technique
No source discloses how the attackers first got in. The following comes from Solar's analysis as reported by secondary outlets and has not been independently verified.
- Tooling: The Telegram-controlled Vasilek backdoor, the DNS tunnelers PartisanDNS and DNSCat2, GOST proxies, and Impacket (including wmiexec) for lateral movement (Threadlinqs; Cyberpress). Threadlinqs maps the activity to 18 MITRE ATT&CK techniques, including RDP (T1021.001), SMB/admin shares (T1021.002) and masquerading (T1036.005).
- Persistence through masquerading: Malicious Windows services were named to look legitimate, for example "Windows Insiders Service" and "VMware Auth Adapter" (Cyberpress).
- Abuse of dormant software: Solar found a previously undocumented loader,
authd.exe, inside a VMware Tools directory. The software had been installed long before the intrusion but was no longer used by administrators. The attackers also replacedvmtools.dll(Cyberpress). - Scheduled operating windows: The loader started payloads on interval timers and cron-style schedules. One GOST tunnel ran only on Saturdays from 22:00 to 23:00. Vasilek and another GOST instance started once, eight hours after their service launched. Solar assesses that this was meant to reduce the chance of detection (Cyberpress).
- Attribution: Solar tracks the group as "Partisan Zmiy." Attribution rests on overlapping infrastructure and techniques (Cyberpress). Threadlinqs rates it medium confidence. The group's own claim now supports it, with the timeline caveat described above.
What Organizations Should Do
- Hunt for Telegram and DNS-based command and control. Flag servers making connections to Telegram API endpoints, and baseline DNS query volume and entropy to catch tunneling tools such as DNSCat2. Domain controllers and management servers should almost never talk to Telegram.
- Audit services against known-good baselines. Look for services whose names imitate VMware, Windows Update/WSUS or "Insider" components but whose binaries are unsigned, recently modified or stored in unusual paths. Check the integrity of
vmtools.dlland anything unexpected in VMware Tools directories. - Remove or monitor dormant software. Unused agents and tools (VMware Tools on hosts that no longer need it, legacy management clients) give attackers places to hide. Uninstall them, or put them under file-integrity monitoring.
- Look for activity that runs on a schedule. Correlate outbound connections by time of day and day of week. A tunnel that comes up for one hour every Saturday night is easy to miss in a daily review but stands out in a weekly one.
- Restrict trusted-relationship paths. Hub organizations should segment connections to subsidiary and partner institutions, enforce least privilege on cross-organization accounts, and log administrative access that crosses those boundaries. Connected organizations should treat traffic from the hub as untrusted until it is verified.
- Scope investigations past the first artifact. Keep logs long enough to cover realistic dwell times (24 months or more for critical infrastructure). Treat attacker or third-party claims of an earlier entry date as leads to investigate, not as noise.
Sources: Belarusian hacktivists admit to 2023 breach of Russian state health... | Belarusian hackers claim 2023 hack of Moscow health network | Belarusian hacktivists admit to 2023 breach of Russian state health... | Belarusian Cyber Partisans maintain two-year Threadlinqs | Vasilek Backdoor Breach: Russian Healthcare Network Hacked | Partisan Zmiy Hackers Use Telegram-Controlled Vasilek Backdoor to S... | Incydent FELG — FELG | Поставка сертификатов на… — тендер №0173200001426001677