Researchers at Russian cybersecurity firm Solar say Belarusian hacktivists spent nearly two years inside the network of a Russian healthcare organization. The intrusion was discovered in December 2025, with the earliest signs traced to early 2024. The targeted organization was not identified, but Solar said it operated extensive infrastructure with connections to numerous other healthcare bodies, potentially enabling the attackers to reach additional victims.

The hackers accessed sensitive medical data but did not disrupt or destroy systems. Solar researchers believe the lack of destructive activity was deliberate, as maintaining access was more valuable for espionage and trusted-relationship attacks, where a compromised organization is used to infiltrate other trusted partners.

The intrusion is attributed to the Belarusian Cyber Partisans, a group known for disruptive attacks against Belarusian and Russian targets. Among the tools used was Vasilek, a Windows backdoor that communicates via Telegram and can execute commands, transfer files, capture screenshots, and record keystrokes. Solar noted that Telegram restrictions in Russia made the malware's communications less reliable, but hackers can switch to other methods.

The Cyber Partisans emerged after Belarus's disputed 2020 presidential election and have increasingly targeted Russian organizations since the start of the Ukraine war. In July, Russia's Supreme Court designated the group an extremist organization, the first time Russia applied that label to a hacking group. The Cyber Partisans did not respond to a request for comment. The group previously said of the designation: "They can't stop us, so they're at least doing something to show they're useful."