#Vasilek
Tactical group ADAM destroyed a Russian 2B9 Vasilek mortar. t.me/noel_reports...
NOELREPORTS 🇪🇺 🇺🇦
Tactical group ADAM destroyed a Russian 2B9 Vasilek mortar.
t.me
November 1, 2023 at 2:43 PM
Gunners of the 17th separate tank brigade destroyed a Russian D-30 howitzer and a 2B9 Vasilek mortar. t.me/noel_reports...
NOELREPORTS 🇪🇺 🇺🇦
Gunners of the 17th separate tank brigade destroyed a Russian D-30 howitzer and a 2B9 Vasilek mortar.
t.me
November 10, 2023 at 7:55 AM
Hackers Hide Vasilek Backdoor Inside VMware Tools to Target Medical Organizations
Hackers Hide Vasilek Backdoor Inside VMware Tools to Target Medical Organizations
Hackers concealed the Vasilek backdoor inside an existing VMware Tools installation during a prolonged intrusion at a medical organization. The attackers maintained access for approximately two years, exposing sensitive medical information while leaving systems operational rather than launching a destructive attack. The earliest evidence dates to early 2024. Investigators found signs of remote command execution, followed by movement through legitimate remote desktop access and Windows file sharing. The report does not establish the original entry point, so phishing or vulnerability exploitation cannot be confirmed. Solar 4RAYS researchers identified an updated Vasilek build and a previously undocumented loader during an investigation that began in December 2025. Solar said in a report shared with Cyber Security News (CSN) that overlapping infrastructure and techniques linked the intrusion to Partisan Zmiy. The organization maintained two-way trust relationships with numerous subsidiary medical institutions. Researchers believe that access encouraged espionage over disruption, creating opportunities to reach connected organizations. The case adds to concerns highlighted by backdoors targeting healthcare organizations that also conceal malicious activity behind familiar software and network services. Hackers Hide Vasilek Backdoor Inside VMware Tools VMware Tools had been installed legitimately long before the intrusion, but administrators were not using it. Its installation directory became a trusted yet unmonitored location where attackers placed malicious components with names resembling genuine virtualization software. The report describes abuse of that installation, not a compromised vendor update. Shortly before discovery in December 2025, the attackers replaced a legitimate VMware library with malicious code and preserved the original under another name, apparently to allow restoration. The replacement lacked a digital signature, unlike the genuine library. Solar describes the substitution as a mechanism for maintaining access. This use of familiar software locations echoes malware hiding beside software in other backdoor research, although the campaigns are separate. Investigators also found Windows services with plausible display names, allowing malicious libraries and the custom loader to blend into routine service listings. Timestamps of malicious services (Source – Solar) The loader launched tools according to a fixed schedule. One GOST tunnel operated every Saturday from 10 p.m. to 11 p.m., while another tunnel and Vasilek started once, eight hours after the service began. Researchers interpreted the limited evening window as a likely backup connection. Other details suggested deliberate concealment. Attackers altered file timestamps to resemble legitimate VMware components and reused the same paths for different tools. The loader configuration also referenced a server-specific Windows update repository, indicating that deployment followed reconnaissance rather than relying entirely on generic settings. Telegram Control and Detection Gaps Vasilek is a 32-bit Windows backdoor first publicly described in 2025. Solar analyzed internal version 1.5.8, whose command table contained 59 entries, including aliases. Its capabilities include executing commands, transferring files, recording keystrokes, capturing screenshots, collecting clipboard contents, and manipulating mouse input. Operators issued instructions through a Telegram group using the public Bot API. They posted on behalf of the group to conceal their personal accounts, while the malware returned results to the same chat. Corporate proxy settings helped its connections follow the route used by legitimate traffic. Telegram was only one access channel. DNSCat2, PartisanDNS, and a GOST-plus-3proxy chain provided alternatives, making a single blocked service insufficient. Similar backdoors using DNS tunneling illustrate how attackers can hide control traffic within ordinary network activity, without establishing a connection between these campaigns. The backdoor also checked the infected computer’s name before activating, hindering analysis elsewhere. Solar recommends checking signatures in trusted software directories and investigating antivirus alerts rather than simply deploying protection. Responders should hunt for additional tunnels, proxy chains, lateral movement tools, and delayed destructive payloads. Security logs preserved service creation events and traces of remote command execution, giving investigators evidence to reconstruct parts of the intrusion after the attackers had already changed files and settings. The indicators below retain the source’s exact values. Solar’s narrative associates the substituted VMware library with Vasilek, but its detailed indicator appendix labels that sample as loading PartisanDNS. Both descriptions are preserved rather than silently reconciled; shared hosting addresses and legitimate artifacts also require contextual interpretation. Indicators of compromise (IoCs):- Type Indicator Description MD5 a6af32b1381d8985049e2d5ec1889bd9 PartisanDNS sample associated with the first listed system library. MD5 338f7eafdfe45e93e57889ebd064d0d5 UPX-packed DNSCat2 sample appearing under two library paths. MD5 39e64553b7ddf579240e6642042e6840 UPX-packed DNSCat2 sample. MD5 a6ce67f063fce60954bb6cea4c969aac Additional PartisanDNS sample, including a backup copy. MD5 1199d2f2b1a58435113555b02172bc79 UPX-packed DNSCat2 sample. MD5 ccf73d3b1e9c625d79ce2c76650ca3e7 Custom loader-scheduler. MD5 6b21d7574b53b753bfdc2acf9c389a90 3proxy sample occupying a VMware-themed executable path. MD5 560397a1bfb7fc32f7eeb7794183993d Vasilek sample occupying the same executable path. MD5 041a3ae432840507a755a79a22a1237a GOST sample in the VMware Tools directory. MD5 2538be4331f69dbf4a9b79565fd39581 PartisanDNS executable. MD5 f34430fb88bda6c904c57facab761fc2 GOST sample in the WSUS repository, deleted before examination. MD5 86f330eb072216ffc807aff4013950f9 Substituted VMware library; appendix identifies it as loading PartisanDNS. SHA-1 bdeac4b8e9a3c48661adf0c2ee5f05b58cee76eb PartisanDNS sample. SHA-1 ed999aaaf1d032c76a51f4aececb99d06c371b33 UPX-packed DNSCat2 sample appearing under two library paths. SHA-1 cd61f92873625dd25a31f414617347d1fa132747 UPX-packed DNSCat2 sample. SHA-1 56df605a33fb77c91bdb92033efe983f336deb23 Additional PartisanDNS sample. SHA-1 efe3503bd021de67e884878c6de1e8b110ed2ee7 UPX-packed DNSCat2 sample. SHA-1 42f5cbbe0feba3e31ac8642791dd48eef8eae123 Custom loader-scheduler. SHA-1 3b1424176c9c1083b79961783b38f5176ff99fee 3proxy sample. SHA-1 3834c4c83cf9758385347a8b34a3e20e17aced3b Vasilek sample. SHA-1 f2fb4a3ba5802df7ae83ac7fb362bce45223312b GOST sample in the VMware Tools directory. SHA-1 d93f810fa02c3d4391810ab512519d89f2f0ceee PartisanDNS executable. SHA-1 c4e623ab0a15db0896bf8a68eb9b45ebe6ae2f28 Unknown WSUS-themed file, deleted before examination. SHA-1 23831129ad88da40cd0bdeae2350f956ca0b2db2 GOST sample in the WSUS repository. SHA-1 4335474d9fd48d7d28e244802e210f1e78dc2f3a Substituted VMware library. SHA-256 cc8c707bf49c0cdb79b806d41df6254efc0e9f566a02d223871550f414469d13 PartisanDNS sample. SHA-256 e5c6b6d37ff168def37dfd86c636e512be3ed7ead9a2dc93d5c741c42b47c1f1 UPX-packed DNSCat2 sample appearing under two library paths. SHA-256 07381d79670129277211a4373e5518799a54b427946602539463ec2dd9cdb5e7 UPX-packed DNSCat2 sample. SHA-256 4f0e23a83d83d901c76353d8b9b6ee2940eb63d531ad15f736193903b5c7c8c3 Additional PartisanDNS sample. SHA-256 8c37c4b1f168219a1ce495c9822730981b20ff03d937ddcd8795fca14a9b7869 UPX-packed DNSCat2 sample. SHA-256 5bc4fa9916c0883d45cb85639e328ed484dc75f4dfda294eb52f4b8b612889f2 Custom loader-scheduler. SHA-256 c499fab59acbb1750e1e0e5a3c51d119ccd6374e5f0b45639f29598720222766 3proxy sample. SHA-256 87e713f9b6ae14d97d3fa4d1a882c029e7e963d844d9c93ea383cab3d46a949c Vasilek sample. SHA-256 d7aedc020ce832334abf0d03986da31f41cb2191355f25b17989dcfa8bb2775b GOST sample in the VMware Tools directory. SHA-256 e55431d6f15aa78ada3f60ed30a3f32b444b952bdc53a652546c1820f8bfa513 PartisanDNS executable. SHA-256 5076286c26f2a5c7dd7f507365fe404db2b05d39b350c463faa053baa37b3742 GOST sample in the WSUS repository. SHA-256 125ead2c3b1d0f7aee03d13b927744ec8dc1d046912ce73efc9c5a10243b99dc Substituted VMware library. IP address 172.67.210[.]25 Source-listed network indicator, labeled Cloudflare; shared infrastructure requires contextual assessment. IP address 104.21.34[.]242 Source-listed network indicator, labeled Cloudflare; shared infrastructure requires contextual assessment. IP address 199.59.243[.]228 Source-listed network indicator, labeled Amazon. Domain okkgb[.]com Network indicator published by Solar. Domain c-oh[.]com Network indicator published by Solar. Domain 89e[.]org Network indicator published by Solar. Domain parker-inc[.]com Network indicator published by Solar. Domain c0ce[.]org DNSCat2 command-and-control domain detected in the incident. Domain p7cp[.]org DNSCat2 command-and-control domain detected in the incident. Domain gov-by[.]com Reused command-and-control domain overlapping earlier reporting. Domain f91j[.]org DNSCat2 command-and-control domain detected in the incident. Domain w3a01[.]net DNSCat2 command-and-control domain detected in the incident. Historical domain 0ce[.]org Previously reported domain included for infrastructure comparison. Historical domain 7cp[.]org Previously reported domain included for infrastructure comparison. Historical domain 3a01[.]net Previously reported domain included for infrastructure comparison. Historical domain 91j[.]org Previously reported domain included for infrastructure comparison. DGA domain vpnosljjk[.]pro PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]top PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]link PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]cyou PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]pro PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]me PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]my PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]buzz PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]info PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]space PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]in PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]sbs PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]work PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]casa PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]lol PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]lat PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]net PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]org PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]com PartisanDNS domain-generation indicator. File path C:\Windows\System32\msadcs32.dll PartisanDNS library; multiple samples occupied this path. File path C:\Windows\System32\msadcs32.bak Backup-path copy of a PartisanDNS sample. File path C:\Windows\System32\tpvmmon.dll DNSCat2 library launched through a Windows service. File path C:\Windows\system32\omega.dll Additional path for the same UPX-packed DNSCat2 sample. File path C:\Windows\System32\aweman32.dll DNSCat2 library launched through a Windows service. File path C:\Windows\system32\uplay_r164.dll UPX-packed DNSCat2 library. File path C:\Program Files\VMware\VMware Tools\authd.exe Custom loader-scheduler masquerading as a VMware component. File path C:\Program Files\VMware\VMware Tools\rpctool32.exe Path occupied by both 3proxy and Vasilek samples during the campaign. File path C:\Program Files\VMware\VMware Tools\vmtoolsd32.exe GOST executable with altered timestamps. File path C:\Windows\fstab.exe PartisanDNS executable. File path C:\Update\169\WSUSSCAN.exe Unknown file deleted before investigation. File path E:\WSUS\UpdateServicesPackages\WsusService.exe GOST executable disguised as a WSUS component. File path C:\Program Files\VMware\VMware Tools\vmtools.dll Replaced VMware library; narrative links it to Vasilek, appendix says it loads PartisanDNS. File path C:\Windows\System32\vmtoolsd.exe Executable associated with a service displayed as “VMware Service”; payload unspecified. File path C:\Program Files\VMware\VMware Tools\gost.yml GOST proxy configuration recovered in command-and-control exchanges. File name vmtoolsd.dll Original legitimate VMware library renamed and retained, apparently for restoration. File name vmtoolsd.exe Legitimate VMware component name imitated by attacker tooling; not independently malicious. File name rpctool.exe Legitimate VMware component name imitated by attacker tooling; not independently malicious. File name new.bak Downloaded replacement backdoor used during self-update. File-name pattern old-<timestamp>.bak Previous backdoor executable renamed during self-update. File-name notation old-.bak Source shorthand for the replaced backdoor backup. File name MySong.mp3 Hardcoded audio filename referenced by an apparent developer debugging function. File-name template [HOSTNAME]-tun.yml Telegram attachment filename shown in the recovered exchange. File-name pattern C:\Windows\__<unix timestamp>.<microseconds> Remote command-output artifact consistent with Impacket execution. UNC path pattern \\127.0.0.1\ADMIN$\__<unix timestamp>.<microseconds> Remote command-output destination; loopback address is not external attacker infrastructure. UNC path pattern \\127.0.0.1\ADMIN$\__<ts>.<us> Alternate notation appearing in the source’s MITRE matrix. Tool filename wmiexec.py Impacket tool associated with the observed command-output pattern; legitimate dual-use tool. Executable name cmd.exe Windows command interpreter used in observed execution; not independently malicious. Service name tpvmmon Malicious service displayed as “Windows Insiders Service.” Service name aweman32 Malicious service displayed as “Windows Channels Service.” Service name msadcs32 Malicious service displayed as “Sybase Inc. Product File.” Service name uplay_r164 Malicious service displayed as “Access FT Imager Service.” Service name vmauad Loader service displayed as “VMware Auth Adapter.” Service artifact AppMgmt Legitimate Windows service whose parameters were apparently temporarily altered. Registry path SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System Legitimate policy location inspected during privilege-elevation attempts. Registry value ConsentPromptBehaviorAdmin UAC policy value checked by the backdoor; not independently malicious. URL template https://api.telegram.org/bot<token>/<method> Legitimate Telegram API endpoint template assembled for command and control; token and method are placeholders. Telegram chat ID -1002113172843 Group identifier visible in recovered command-and-control exchanges. Telegram account name GroupAnonymousBot Legitimate Telegram identity used to post commands anonymously on behalf of the group. Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC The post Hackers Hide Vasilek Backdoor Inside VMware Tools to Target Medical Organizations appeared first on Cyber Security News .
cybersecuritynews.com
October 7, 2026 at 8:21 AM
ACHILLES unit of the 92nd Assault Brigade with a compilation of destroyed Russian equipment. Among the losses are a BTR-80A, 2 FAGOT ATGM positions, 2B9 Vasilek mortar and an ammunition site.
February 9, 2024 at 6:46 PM
Vasilek backdoor embedded in VMware Tools targets healthcare orgs with multi-layered C2 — a stealth outbreak. #cybersecurity #malware #Vasilek #VMware #Healthcare #Malware #C2 #Cybersecurity https://thedailytechfeed.com/hackers-embed-vasilek-backdoor-in-vmware-tools-to-spy-on-hospitals/
October 7, 2026 at 8:05 AM
❗️Strike UAV operators of the 🇺🇦105th Border Guard Detachment named after Prince Volodymyr the Great struck a jet-powered Geran-5 drone, Vasilek automatic mortars, fuel and ammunition depots, electronic warfare systems and radar stations, as well as enemy vehicles and fortification shelters
September 23, 2026 at 12:44 PM
Ukrainian troops captured the 2B9 Vasilek, a Russian automatic 82 mm gun-mortar, in Kursk Oblast

📷https://t.me/ButusovPlus/12883
August 19, 2024 at 7:11 PM
“It’s rare that we get to observe what happens [on-site] after an attack is completed…It’s always entertaining,” said one of the hackers, who goes by the name Vasilek.
May 22, 2026 at 1:40 PM
His name is Vasil (Vasilek for "friends"). He’s a warloсk now, but he used to be a wizard until he lost the ability to cast spells. He’s smart but terribly annoying. That’s why he never managed to romance anyone, haha 💀
I can answer questions about Vasil.
| #bg3 #BG3Tav #tav |
January 5, 2025 at 2:07 PM
Cyber Partisans hid in a Russian health network for 2 years, taking orders over Telegram. https://intel.threadlinqs.com/threat/TL-2026-2950 #ThreatIntel #Vasilek #PartisanDNS #DNSCat2
October 5, 2026 at 8:26 PM
The 1st Assault Batallion of the 92nd separate assault brigade showed how it destroyed several pieces of Russian equipment. Among them a 120-mm mortar, 2B9 Vasilek mortar, MT-12 Rapira mortar, a BTR-82A and about 20 Russian infantrymen. t.me/noel_reports...
t.me
December 31, 2023 at 1:56 PM
meet the first #oc i ever drew for a tabletop game ~ Ellowen Hyacinth Vasilek🪷

forest nymph, talented performer, and a hopeless flirt, who charms her way out of problems…

definitely one of the most chaotic characters i’ve ever roleplayed <3

#tabletop #art #digitalart #dnd #characterart #ttrpg
September 19, 2025 at 5:24 PM
July 5, 2024 at 7:07 PM
Happy New Year! :Р
(It's already 00:17 on my watch )

( characters are designated by numbers )

1) Tsumi (Central Mass Array)
2)Sasha/Alexander (Abandoned Harbour)
3) Red
4)Vasya/Vasily (Whirlwind Wasteland)
5) Elise
6)Aloy
7)Vasya/ Vasilek/knapweed
8) Luna

#fe2 #floodescape2 #fe2fanart
December 31, 2024 at 2:17 PM
Partisan Zmiy、Telegram制御のバックドア「Vasilek」で医療機関ネットワークをスパイ

ハッカー集団Partisan Zmiyは、Telegramで制御するバックドア「Vasilek」を、DNSトンネルやプロキシツールと併用し、ある医療機関への侵入状態を2年近く維持していました。Solar 4RAYSの調査チームは2025年12月に調査へ加わり、2024年初頭にさかのぼる痕跡を確認しています。 調査のき
Partisan Zmiy、Telegram制御のバックドア「Vasilek」で医療機関ネットワークをスパイ
ハッカー集団Partisan Zmiyは、Telegramで制御するバックドア「Vasilek」を、DNSトンネルやプロキシツールと併用し、ある医療機関への侵入状態を2年近く維持していました。Solar 4RAYSの調査チームは2025年12月に調査へ加わり、2024年初頭にさかのぼる痕跡を確認しています。 調査のき
blackhatnews.tokyo
October 7, 2026 at 12:23 PM
i made this robot in a game when i was around 14.....
back then i was into votoms and a kinda insensitively into real military hardware so you can really see that in the design
this stuff is alright but you can maybe see through this that i'd like to develop a more personal design style soon
July 22, 2026 at 12:50 AM
Ukrainian Armed Forces soldiers from an assault group participating in the kursk operation shared footage of a captured 82mm automatic mortar "Vasilek" and other items found at a captured Russian stronghold.

t.me/noel_reports...
NOELREPORTS 🇪🇺 🇺🇦
Ukrainian Armed Forces soldiers from an assault group participating in the kursk operation shared footage of a captured 82mm automatic mortar "Vasilek" and other items found at a captured Russian stro...
t.me
August 19, 2024 at 9:10 PM
A medical organization’s systems kept running while attackers remained inside for about two years and sensitive medical information was exposed.…

https://en.hacks.gr/chaker-emeinan-peripoy-dyo-chronia-se-iatriko-organismo-kai-ektethikan-eyaisthites-plirofories/

#MedicalData #VMwareTools #Vasilek
October 7, 2026 at 7:59 AM
8. NE of Hama city/Kafraa
Not a SAA vehicle loss here, but leaving this here as I find it interesting to see an HTS Landrover mounting a 2B9 Vasilek automatic mortar, before the attack on Kafraa.
Rebels captured both the village + Mount Kafraa on 03.12.24 in shaping operations prior to entering Hama
December 6, 2024 at 5:56 PM
Cybercriminelen houden twee jaar lang medische organisatie in gijzeling met geav

Onderzoekers van Solar 4RAYS hebben in december 2025 een langdurige cyberaanval op een medische organisatie ontdekt, waarbij de Vasilek-backdoor en een voorheen onbekende loader werden ingezet. De vroegste spor...
Cybercriminelen houden twee jaar lang medische organisatie in gijzeling met geavanceerde backdoor.
Onderzoekers van Solar 4RAYS hebben in december 2025 een langdurige cyberaanval op een medische organisatie ontdekt, waarbij de Vasilek-backdoor en een voorheen onbekende loader werden ingezet. De vroegste sporen van de inbraak dateren van begin 2024. Gedurende deze periode van ongeveer twee jaar wisten de aanvallers gevoelige medische informatie bloot te leggen, terwijl ze de systemen operationeel hielden. De getroffen organisatie onderhield vertrouwensrelaties met diverse dochterondernemingen binnen de medische sector, waardoor de aanvallers toegang konden verkrijgen tot verbonden organisaties. De aanval illustreert een trend waarbij backdoors, specifiek gericht op de gezondheidszorg, kwa...
newsfacts.info
October 7, 2026 at 8:00 AM
The 2B9 Vasilek (2Б9 "Василёк" - Cornflower) also known as Vasilyek,[2] AM 289 Vasilyek[3] or AM 2B9 Vasilyek,[3] is an automatic 82 mm gun-mortar developed in the Soviet Union in 1967 and fielded with the Soviet Army in 1970.
March 13, 2025 at 2:26 PM
The only saints worth considering are Mary Magdalene, Joan of Arc, and Francis of Assisi. The rest are neurotic, like Teresa of Ávila, or fictitious a/o frauds, like Padre Pio.
www.theguardian.com/music/2026/s...
Honegger: Jeanne d’Arc au Bûcher album review – faultless recording of an eclectic masterpiece
Honegger’s multifaceted 1935 composition about the French saint is brought to life in spine-tingling detail by Lukáš Vasilek, actors and musicians
www.theguardian.com
September 25, 2026 at 2:15 PM
Honegger: Jeanne d’Arc au Bûcher album review – faultless recording of an eclectic masterpiece

Bonnet/Dutrieux/Czech Philharmonic/Vasilek(Animal Music)Honegger’s multifaceted 1935 composition about the French saint is brought to life in spine-tingling detail by Lukáš Vasilek, the Czech...
Honegger: Jeanne d’Arc au Bûcher album review – faultless recording of an eclectic masterpiece
Honegger’s multifaceted 1935 composition about the French saint is brought to life in spine-tingling detail by Lukáš Vasilek, actors and musicians
www.theguardian.com
September 25, 2026 at 7:46 AM