Solar 4RAYS: Partisan Zmiy hid an updated Vasilek backdoor inside an unused VMware Tools install at a medical organisation, keeping access for about two years with a weekly one-hour GOST tunnel
Solar 4RAYS, the threat research team of Russian security company Solar, published an investigation (reported by Cyber Security News on 7 October 2026) into a long intrusion at a medical organisation that it links to the group it calls Partisan Zmiy, based on overlapping infrastructure and techniques. The earliest evidence dates to early 2024 and the investigation began in December 2025, so the attackers had access for about two years; how they first got in is not known. They ran commands remotely, then moved through the network over legitimate remote desktop and Windows file sharing. VMware Tools had been installed long before but was not in use, so its folder became a trusted, unwatched place to drop malicious files named like real virtualisation components, with timestamps changed to match. Shortly before discovery the attackers swapped a genuine VMware library for an unsigned malicious one, keeping the original under another name. Windows services with plausible names started a previously undocumented loader, which ran an updated Vasilek backdoor and GOST tunnels on a schedule, including one tunnel open only from 10pm to 11pm each Saturday, likely as a backup way in. The organisation had two-way trust relationships with many subsidiary medical institutions, and the researchers read the case as espionage rather than disruption. Solar did not name the victim. Primary: Solar 4RAYS blog (Russian); wire: Cyber Security News.
- Product
- Windows servers with legitimately installed but unused VMware Tools (abused install path; not a VMware vulnerability)
- Versions
- n/a — intrusion
- Exploited in Australia?
- unknown
- Patch to
- Remove agent software you don't use, such as VMware Tools on hosts that are not VMware guests. Alert on unsigned DLLs in vendor folders under Program Files, new services with vendor-like names, and file timestamps that don't match install dates. Watch for scheduled outbound tunnels (GOST and similar) at odd hours, and review two-way trusts with partner or subsidiary organisations.
Primary: Solar 4RAYS — Partisan Zmiy: атаковала медицинскую организацию (blog, Russian) · Cyber Security News — Hackers hide Vasilek backdoor inside VMware Tools to target medical organizations (7 Oct 2026)
