VYPR
researchPublished Oct 7, 2026· 1 source

Vasilek Backdoor Lurks in VMware Tools for Two Years, Targeting Medical Sector

Attackers maintained a two-year presence within a medical organization by hiding the Vasilek backdoor inside legitimate VMware Tools installations, evading detection and exfiltrating data.

Threat actors have been discovered maintaining a persistent, two-year foothold within a medical organization by cleverly disguising the Vasilek backdoor within legitimate VMware Tools installations. This sophisticated intrusion, which began as early as 2024, focused on espionage rather than destructive actions, allowing attackers to exfiltrate sensitive medical information while keeping systems operational. The full extent of the data compromised and the specific types of medical information targeted remain under investigation.

Researchers from Solar 4RAYS, who began their investigation in December 2025, identified an updated Vasilek build and a novel loader component. Their analysis linked the intrusion to the threat group Partisan Zmiy through overlapping infrastructure and shared techniques. The targeted medical organization maintained complex trust relationships with numerous subsidiary institutions, suggesting the attackers aimed to leverage this access for broader espionage across connected entities.

The attackers exploited the presence of VMware Tools, which was legitimately installed but not actively used by administrators. This created an unmonitored, trusted location where malicious components could be placed, disguised with names similar to genuine VMware files. Notably, the attackers did not exploit a compromised vendor update but rather abused the existing installation directory. In one instance, shortly before discovery, they replaced a legitimate VMware library with malicious code, keeping the original under a different name for potential restoration, though the replacement lacked a digital signature.

Further evading detection, the threat actors employed Windows services with plausible display names, allowing malicious libraries and a custom loader to blend seamlessly into routine system operations. This loader was configured to launch various tools on a fixed schedule, including a GOST tunnel that operated weekly and Vasilek itself, which initiated its connection eight hours after the service started. The limited operational window for some components suggests a deliberate attempt to minimize their online footprint and avoid triggering security alerts.

File timestamps were manipulated to mimic legitimate VMware components, and attackers reused the same file paths for different tools, adding layers of obfuscation. The loader's configuration also referenced a server-specific Windows update repository, indicating that deployment was tailored after initial reconnaissance, rather than relying on generic settings. This meticulous approach highlights the attackers' commitment to stealth and persistence.

Vasilek, a 32-bit Windows backdoor first publicly documented in 2025, offers a range of espionage capabilities. The version analyzed by Solar (1.5.8) included functionalities for executing commands, transferring files, capturing keystrokes and screenshots, collecting clipboard data, and manipulating mouse input. Command and control (C2) communications were primarily managed through a private Telegram group, with operators posting instructions via the public Bot API and receiving results in the same chat, further obscuring their identities.

To ensure resilient command and control, the attackers utilized multiple communication channels beyond Telegram. These included DNSCat2, PartisanDNS, and a GOST-plus-3proxy chain. This multi-layered approach meant that blocking a single service would not disrupt their operations. The backdoor also incorporated a check for the infected computer's name before activation, a tactic designed to hinder analysis and reverse engineering efforts.

Solar recommends that organizations enhance their security posture by verifying digital signatures in trusted software directories and actively investigating antivirus alerts rather than solely relying on automated protection. Security teams should proactively hunt for additional communication tunnels, proxy chains, lateral movement tools, and potential destructive payloads. While attackers actively alter files and settings, security logs often preserve crucial evidence, such as service creation events and traces of remote command execution, which can aid investigators in reconstructing the timeline and methods of an intrusion.

Synthesized by Vypr AI