Skip to content
Security & Trust

Solar says hackers stayed in a Russian health network for nearly two years

The intruders reportedly accessed medical data but destroyed nothing. Solar believes the quiet was deliberate.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Solar says hackers stayed in a Russian health network for nearly two years
In brief
  • Russian firm Solar says Belarusian hacktivists sat in a healthcare network for nearly two years, reached medical data, and disrupted nothing.
  • Solar believes the quiet was deliberate, to keep access for espionage and attacks that exploit trusted connections to other organisations.
  • Leaders should ask how long an intruder could stay unseen, and which partner connections could carry one in.

Damage is a poor test of whether someone is inside

When systems keep running, it is easy to assume nobody is there. A report on a Russian healthcare network suggests that assumption can fail. The lesson here is that a quiet network and a clean network are different things.

Solar is a Russian security firm owned by Rostelecom, a state-controlled telecom group. It says it discovered the intrusion in December 2025. Its team found the first traces dating back to early 2024. Solar blames the Belarusian Cyber Partisans, an activist hacking group.

Nearly 2 years
Time inside the network
Source: Solar, as reported by The Record (October 5, 2026)
Early 2024
Earliest signs of compromise
Source: Solar, as reported by The Record (October 5, 2026)
December 2025
Date Solar discovered the intrusion
Source: Solar, as reported by The Record (October 5, 2026)

Why a patient hacker is a different problem

Solar says the intruders reached sensitive medical data. It says they left the victim's systems working and destroyed nothing.

Solar offers a reason, framed as a belief. It thinks the hackers stayed quiet to keep their access for "further espionage and trusted-relationship attacks".

A trusted-relationship attack works through a middleman. Attackers first break into an organisation that others already trust. They then use that trust to reach the real target.

That is why this victim matters beyond its own walls. Solar describes a large network with links to many other healthcare organisations. Solar says those links could have given the hackers a route to other targets. The report does not say whether any of those partners were reached.

How the backdoor works

Solar named one tool: Vasilek, a Windows backdoor. A backdoor is hidden software that lets an attacker control a computer from afar. Kaspersky first documented Vasilek in 2025. The copy Solar studied was a newer build.

Vasilek talks to its operators through Telegram, the messaging service. Traffic to a mainstream app can look ordinary. Once installed, Vasilek can:

Collect information about the infected computer. Run Windows commands. Start and stop processes. Transfer files. Capture screenshots. Record keystrokes. Update or delete itself.

Telegram restrictions in Russia made Vasilek's contact with its control servers less reliable, Solar noted. The researchers added that hackers can switch to other ways of communicating. A blocked channel is an obstacle, not a barrier.

What the report does not settle

Readers should weigh the source. Solar belongs to a state-controlled company. The victim is not named, so outsiders cannot check the claims. The Cyber Partisans did not respond to The Record's request for comment.

The context is political. The group emerged after the disputed 2020 Belarusian presidential election. It has claimed attacks on Belarusian state institutions and the country's railway system. In July, Russia's Supreme Court named it an "extremist organization". The Record reports this was the first time Russia used that label for a hacking group.

The group's side of the story is thin. Its only quoted response is to the court ruling: "we will keep destabilizing the dictatorship!"

Questions to put to your security team

The intruder in this account was not noisy. The report gives no sign that an outage or ransom note exposed it. Detection came only in December 2025. Five questions follow.

First, how long could an intruder stay here before we knew? What evidence supports that answer?

Second, do we watch for servers or workstations contacting messaging services such as Telegram?

Third, which partners hold trusted connections into our network? Who monitors those links?

Fourth, if we were the trusted middleman, would our partners hear it from us or from a researcher?

Fifth, do we hunt for quiet activity, such as unexplained file transfers, rather than waiting for something to break?

For healthcare and any sector built on shared connections, the point is simple. The patients behind the data never see the network. They depend on whoever is watching it. A silent network is not proof of a safe one.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: The Record.

Share this insight