Hackers Hide Vasilek Backdoor Inside VMware Tools to Target Medical Organizations
Hackers concealed the Vasilek backdoor inside an existing VMware Tools installation during a prolonged intrusion at a medical organization.
The attackers maintained access for approximately two years, exposing sensitive medical information while leaving systems operational rather than launching a destructive attack.
The earliest evidence dates to early 2024. Investigators found signs of remote command execution, followed by movement through legitimate remote desktop access and Windows file sharing.
The report does not establish the original entry point, so phishing or vulnerability exploitation cannot be confirmed. Solar 4RAYS researchers identified an updated Vasilek build and a previously undocumented loader during an investigation that began in December 2025.
Solar said in a report shared with Cyber Security News (CSN) that overlapping infrastructure and techniques linked the intrusion to Partisan Zmiy.
The organization maintained two-way trust relationships with numerous subsidiary medical institutions. Researchers believe that access encouraged espionage over disruption, creating opportunities to reach connected organizations.
The case adds to concerns highlighted by backdoors targeting healthcare organizations that also conceal malicious activity behind familiar software and network services.
Hackers Hide Vasilek Backdoor Inside VMware Tools
VMware Tools had been installed legitimately long before the intrusion, but administrators were not using it. Its installation directory became a trusted yet unmonitored location where attackers placed malicious components with names resembling genuine virtualization software.
The report describes abuse of that installation, not a compromised vendor update. Shortly before discovery in December 2025, the attackers replaced a legitimate VMware library with malicious code and preserved the original under another name, apparently to allow restoration.
The replacement lacked a digital signature, unlike the genuine library. Solar describes the substitution as a mechanism for maintaining access.
This use of familiar software locations echoes malware hiding beside software in other backdoor research, although the campaigns are separate.
Investigators also found Windows services with plausible display names, allowing malicious libraries and the custom loader to blend into routine service listings.
Timestamps of malicious services (Source – Solar)
The loader launched tools according to a fixed schedule. One GOST tunnel operated every Saturday from 10 p.m. to 11 p.m., while another tunnel and Vasilek started once, eight hours after the service began.
Researchers interpreted the limited evening window as a likely backup connection. Other details suggested deliberate concealment. Attackers altered file timestamps to resemble legitimate VMware components and reused the same paths for different tools.
The loader configuration also referenced a server-specific Windows update repository, indicating that deployment followed reconnaissance rather than relying entirely on generic settings.
Telegram Control and Detection Gaps
Vasilek is a 32-bit Windows backdoor first publicly described in 2025. Solar analyzed internal version 1.5.8, whose command table contained 59 entries, including aliases.
Its capabilities include executing commands, transferring files, recording keystrokes, capturing screenshots, collecting clipboard contents, and manipulating mouse input.
Operators issued instructions through a Telegram group using the public Bot API. They posted on behalf of the group to conceal their personal accounts, while the malware returned results to the same chat.
Corporate proxy settings helped its connections follow the route used by legitimate traffic. Telegram was only one access channel. DNSCat2, PartisanDNS, and a GOST-plus-3proxy chain provided alternatives, making a single blocked service insufficient.
Similar backdoors using DNS tunneling illustrate how attackers can hide control traffic within ordinary network activity, without establishing a connection between these campaigns.
The backdoor also checked the infected computer’s name before activating, hindering analysis elsewhere. Solar recommends checking signatures in trusted software directories and investigating antivirus alerts rather than simply deploying protection.
Responders should hunt for additional tunnels, proxy chains, lateral movement tools, and delayed destructive payloads. Security logs preserved service creation events and traces of remote command execution, giving investigators evidence to reconstruct parts of the intrusion after the attackers had already changed files and settings.
The indicators below retain the source’s exact values. Solar’s narrative associates the substituted VMware library with Vasilek, but its detailed indicator appendix labels that sample as loading PartisanDNS.
Both descriptions are preserved rather than silently reconciled; shared hosting addresses and legitimate artifacts also require contextual interpretation.
Indicators of compromise (IoCs):-
Type Indicator Description MD5 a6af32b1381d8985049e2d5ec1889bd9 PartisanDNS sample associated with the first listed system library. MD5 338f7eafdfe45e93e57889ebd064d0d5 UPX-packed DNSCat2 sample appearing under two library paths. MD5 39e64553b7ddf579240e6642042e6840 UPX-packed DNSCat2 sample. MD5 a6ce67f063fce60954bb6cea4c969aac Additional PartisanDNS sample, including a backup copy. MD5 1199d2f2b1a58435113555b02172bc79 UPX-packed DNSCat2 sample. MD5 ccf73d3b1e9c625d79ce2c76650ca3e7 Custom loader-scheduler. MD5 6b21d7574b53b753bfdc2acf9c389a90 3proxy sample occupying a VMware-themed executable path. MD5 560397a1bfb7fc32f7eeb7794183993d Vasilek sample occupying the same executable path. MD5 041a3ae432840507a755a79a22a1237a GOST sample in the VMware Tools directory. MD5 2538be4331f69dbf4a9b79565fd39581 PartisanDNS executable. MD5 f34430fb88bda6c904c57facab761fc2 GOST sample in the WSUS repository, deleted before examination. MD5 86f330eb072216ffc807aff4013950f9 Substituted VMware library; appendix identifies it as loading PartisanDNS. SHA-1 bdeac4b8e9a3c48661adf0c2ee5f05b58cee76eb PartisanDNS sample. SHA-1 ed999aaaf1d032c76a51f4aececb99d06c371b33 UPX-packed DNSCat2 sample appearing under two library paths. SHA-1 cd61f92873625dd25a31f414617347d1fa132747 UPX-packed DNSCat2 sample. SHA-1 56df605a33fb77c91bdb92033efe983f336deb23 Additional PartisanDNS sample. SHA-1 efe3503bd021de67e884878c6de1e8b110ed2ee7 UPX-packed DNSCat2 sample. SHA-1 42f5cbbe0feba3e31ac8642791dd48eef8eae123 Custom loader-scheduler. SHA-1 3b1424176c9c1083b79961783b38f5176ff99fee 3proxy sample. SHA-1 3834c4c83cf9758385347a8b34a3e20e17aced3b Vasilek sample. SHA-1 f2fb4a3ba5802df7ae83ac7fb362bce45223312b GOST sample in the VMware Tools directory. SHA-1 d93f810fa02c3d4391810ab512519d89f2f0ceee PartisanDNS executable. SHA-1 c4e623ab0a15db0896bf8a68eb9b45ebe6ae2f28 Unknown WSUS-themed file, deleted before examination. SHA-1 23831129ad88da40cd0bdeae2350f956ca0b2db2 GOST sample in the WSUS repository. SHA-1 4335474d9fd48d7d28e244802e210f1e78dc2f3a Substituted VMware library. SHA-256 cc8c707bf49c0cdb79b806d41df6254efc0e9f566a02d223871550f414469d13 PartisanDNS sample. SHA-256 e5c6b6d37ff168def37dfd86c636e512be3ed7ead9a2dc93d5c741c42b47c1f1 UPX-packed DNSCat2 sample appearing under two library paths. SHA-256 07381d79670129277211a4373e5518799a54b427946602539463ec2dd9cdb5e7 UPX-packed DNSCat2 sample. SHA-256 4f0e23a83d83d901c76353d8b9b6ee2940eb63d531ad15f736193903b5c7c8c3 Additional PartisanDNS sample. SHA-256 8c37c4b1f168219a1ce495c9822730981b20ff03d937ddcd8795fca14a9b7869 UPX-packed DNSCat2 sample. SHA-256 5bc4fa9916c0883d45cb85639e328ed484dc75f4dfda294eb52f4b8b612889f2 Custom loader-scheduler. SHA-256 c499fab59acbb1750e1e0e5a3c51d119ccd6374e5f0b45639f29598720222766 3proxy sample. SHA-256 87e713f9b6ae14d97d3fa4d1a882c029e7e963d844d9c93ea383cab3d46a949c Vasilek sample. SHA-256 d7aedc020ce832334abf0d03986da31f41cb2191355f25b17989dcfa8bb2775b GOST sample in the VMware Tools directory. SHA-256 e55431d6f15aa78ada3f60ed30a3f32b444b952bdc53a652546c1820f8bfa513 PartisanDNS executable. SHA-256 5076286c26f2a5c7dd7f507365fe404db2b05d39b350c463faa053baa37b3742 GOST sample in the WSUS repository. SHA-256 125ead2c3b1d0f7aee03d13b927744ec8dc1d046912ce73efc9c5a10243b99dc Substituted VMware library. IP address 172.67.210[.]25 Source-listed network indicator, labeled Cloudflare; shared infrastructure requires contextual assessment. IP address 104.21.34[.]242 Source-listed network indicator, labeled Cloudflare; shared infrastructure requires contextual assessment. IP address 199.59.243[.]228 Source-listed network indicator, labeled Amazon. Domain okkgb[.]com Network indicator published by Solar. Domain c-oh[.]com Network indicator published by Solar. Domain 89e[.]org Network indicator published by Solar. Domain parker-inc[.]com Network indicator published by Solar. Domain c0ce[.]org DNSCat2 command-and-control domain detected in the incident. Domain p7cp[.]org DNSCat2 command-and-control domain detected in the incident. Domain gov-by[.]com Reused command-and-control domain overlapping earlier reporting. Domain f91j[.]org DNSCat2 command-and-control domain detected in the incident. Domain w3a01[.]net DNSCat2 command-and-control domain detected in the incident. Historical domain 0ce[.]org Previously reported domain included for infrastructure comparison. Historical domain 7cp[.]org Previously reported domain included for infrastructure comparison. Historical domain 3a01[.]net Previously reported domain included for infrastructure comparison. Historical domain 91j[.]org Previously reported domain included for infrastructure comparison. DGA domain vpnosljjk[.]pro PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]top PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]link PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]cyou PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]pro PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]me PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]my PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]buzz PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]info PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]space PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]in PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]sbs PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]work PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]casa PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]lol PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]lat PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]net PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]org PartisanDNS domain-generation indicator. DGA domain vfvnfaq[.]com PartisanDNS domain-generation indicator. File path C:\Windows\System32\msadcs32.dll PartisanDNS library; multiple samples occupied this path. File path C:\Windows\System32\msadcs32.bak Backup-path copy of a PartisanDNS sample. File path C:\Windows\System32\tpvmmon.dll DNSCat2 library launched through a Windows service. File path C:\Windows\system32\omega.dll Additional path for the same UPX-packed DNSCat2 sample. File path C:\Windows\System32\aweman32.dll DNSCat2 library launched through a Windows service. File path C:\Windows\system32\uplay_r164.dll UPX-packed DNSCat2 library. File path C:\Program Files\VMware\VMware Tools\authd.exe Custom loader-scheduler masquerading as a VMware component. File path C:\Program Files\VMware\VMware Tools\rpctool32.exe Path occupied by both 3proxy and Vasilek samples during the campaign. File path C:\Program Files\VMware\VMware Tools\vmtoolsd32.exe GOST executable with altered timestamps. File path C:\Windows\fstab.exe PartisanDNS executable. File path C:\Update\169\WSUSSCAN.exe Unknown file deleted before investigation. File path E:\WSUS\UpdateServicesPackages\WsusService.exe GOST executable disguised as a WSUS component. File path C:\Program Files\VMware\VMware Tools\vmtools.dll Replaced VMware library; narrative links it to Vasilek, appendix says it loads PartisanDNS. File path C:\Windows\System32\vmtoolsd.exe Executable associated with a service displayed as “VMware Service”; payload unspecified. File path C:\Program Files\VMware\VMware Tools\gost.yml GOST proxy configuration recovered in command-and-control exchanges. File name vmtoolsd.dll Original legitimate VMware library renamed and retained, apparently for restoration. File name vmtoolsd.exe Legitimate VMware component name imitated by attacker tooling; not independently malicious. File name rpctool.exe Legitimate VMware component name imitated by attacker tooling; not independently malicious. File name new.bak Downloaded replacement backdoor used during self-update. File-name pattern old-<timestamp>.bak Previous backdoor executable renamed during self-update. File-name notation old-.bak Source shorthand for the replaced backdoor backup. File name MySong.mp3 Hardcoded audio filename referenced by an apparent developer debugging function. File-name template [HOSTNAME]-tun.yml Telegram attachment filename shown in the recovered exchange. File-name pattern C:\Windows\__<unix timestamp>.<microseconds> Remote command-output artifact consistent with Impacket execution. UNC path pattern \\127.0.0.1\ADMIN$\__<unix timestamp>.<microseconds> Remote command-output destination; loopback address is not external attacker infrastructure. UNC path pattern \\127.0.0.1\ADMIN$\__<ts>.<us> Alternate notation appearing in the source’s MITRE matrix. Tool filename wmiexec.py Impacket tool associated with the observed command-output pattern; legitimate dual-use tool. Executable name cmd.exe Windows command interpreter used in observed execution; not independently malicious. Service name tpvmmon Malicious service displayed as “Windows Insiders Service.” Service name aweman32 Malicious service displayed as “Windows Channels Service.” Service name msadcs32 Malicious service displayed as “Sybase Inc. Product File.” Service name uplay_r164 Malicious service displayed as “Access FT Imager Service.” Service name vmauad Loader service displayed as “VMware Auth Adapter.” Service artifact AppMgmt Legitimate Windows service whose parameters were apparently temporarily altered. Registry path SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System Legitimate policy location inspected during privilege-elevation attempts. Registry value ConsentPromptBehaviorAdmin UAC policy value checked by the backdoor; not independently malicious. URL template https://api.telegram.org/bot<token>/<method> Legitimate Telegram API endpoint template assembled for command and control; token and method are placeholders. Telegram chat ID -1002113172843 Group identifier visible in recovered command-and-control exchanges. Telegram account name GroupAnonymousBot Legitimate Telegram identity used to post commands anonymously on behalf of the group.
Note: IP addresses and domains are intentionally defanged (e.g., [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM .
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
The post Hackers Hide Vasilek Backdoor Inside VMware Tools to Target Medical Organizations appeared first on Cyber Security News .