Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Pwn2Own 2026 Sees 32 Zero-Days Exploit Samsung S26, Pixel 10, OpenAI Codex
October 7, 2026
Critical OpenSSH Flaws Allow Plaintext Recovery, File Write, and Injection
October 7, 2026
Critical WordPress Flaws Allow XSS, SQL Injection, Data Disclosure
October 7, 2026
Home/CyberSecurity News/Critical VMware Tools Flaw Lets Attackers Install Vasilek Backdoor
CyberSecurity News

Critical VMware Tools Flaw Lets Attackers Install Vasilek Backdoor

Key Takeaways A sophisticated threat actor has been observed embedding the Vasilek backdoor within legitimate VMware Tools installations. The attack chain targeted a medical organization, maintaining...

Sarah simpson
Sarah simpson
October 7, 2026 7 Min Read
3 0

Key Takeaways

  • A sophisticated threat actor has been observed embedding the Vasilek backdoor within legitimate VMware Tools installations.
  • The attack chain targeted a medical organization, maintaining persistence for approximately two years and exposing sensitive data.
  • The attackers leveraged trusted software directories and disguised malicious components with names mimicking genuine virtualization software.
  • The Vasilek backdoor, controlled via Telegram, provides extensive surveillance and control capabilities, including command execution, file transfer, and keystroke logging.
  • No specific vulnerability in VMware Tools was exploited; instead, the existing installation was abused as a stealthy hiding place.

Cybersecurity researchers have uncovered a persistent campaign where attackers integrated the Vasilek backdoor into a medical organization’s VMware Tools installation, maintaining covert access for around two years. This prolonged intrusion, dating back to early 2024, focused on espionage and data exfiltration rather than disruptive attacks, exploiting trust relationships with numerous affiliated medical institutions.

Table Of Content

  • Key Takeaways
  • Stealthy Integration within VMware Tools
  • Vasilek Backdoor: Telegram Control and Detection Challenges

Investigators from Solar 4RAYS, who initiated their probe in December 2025, identified an updated variant of Vasilek and a previously unknown custom loader. Evidence points to initial remote command execution, followed by lateral movement using legitimate remote desktop and Windows file-sharing services. While the initial compromise vector remains unconfirmed, Solar’s analysis, detailed in a report shared with Cyber Security News (CSN), suggests a link to the threat group known as Partisan Zmiy due to overlapping infrastructure and tactics.

The attackers exploited the organization’s extensive network of subsidiary medical institutions, likely using this access for intelligence gathering across connected entities. This incident underscores a growing trend of threat actors camouflaging malicious activities within common software and network services, particularly when targeting the healthcare sector.

Stealthy Integration within VMware Tools

The attackers did not exploit a vulnerability within VMware Tools itself. Instead, they leveraged an existing, legitimate installation of VMware Tools that was present but unused by administrators. This provided a trusted, yet unmonitored, location to deploy their malicious components. These components were deliberately named to resemble authentic virtualization software, further aiding their concealment.

Before their discovery in December 2025, the attackers replaced a legitimate VMware library with their malicious code, carefully preserving the original file under a different name—a tactic likely intended for potential restoration or to avoid immediate detection. Unlike the genuine library, the substituted malicious file lacked a digital signature. Solar described this library substitution as a key mechanism for maintaining persistent access.

This method of hiding malware within familiar software directories is consistent with other backdoor research, highlighting a broader adversary trend of blending into the legitimate operational environment. Furthermore, the attackers created Windows services with innocuous display names, ensuring their malicious libraries and custom loader appeared as routine entries in service listings.

The custom loader was configured to execute its tools on a fixed schedule. For instance, a GOST tunnel activated every Saturday evening from 10 p.m. to 11 p.m., while another tunnel and the Vasilek backdoor launched once, eight hours after the service started. Researchers interpret this limited operational window as a potential backup communication channel. Further evidence of concealment included the alteration of file timestamps to match legitimate VMware components and the reuse of file paths for different malicious tools. The loader’s configuration also referenced a server-specific Windows update repository, indicating that deployment followed meticulous reconnaissance rather than generic settings.

Vasilek Backdoor: Telegram Control and Detection Challenges

Vasilek, a 32-bit Windows backdoor first publicly documented in 2025, was analyzed by Solar in version 1.5.8. This variant features a comprehensive command table with 59 entries, including aliases, enabling a wide array of malicious actions. Its capabilities encompass remote command execution, file transfers, keystroke logging, screenshot capture, clipboard content collection, and mouse input manipulation.

Operators controlled Vasilek through a Telegram group, utilizing the public Bot API. They posted commands anonymously on behalf of the group, and the malware returned results to the same chat, further obscuring their identities. The backdoor’s connections were routed through corporate proxy settings, allowing them to blend with legitimate network traffic.

Telegram was not the sole command-and-control channel. The attackers also employed DNSCat2, PartisanDNS, and a GOST-plus-3proxy chain, ensuring multiple redundant access points. This multi-channel approach means blocking a single service would be insufficient to disrupt their operations. The use of DNS tunneling for C2 traffic highlights how attackers can hide malicious communications within ordinary network activity, though these campaigns are not necessarily linked.

To thwart analysis, the Vasilek backdoor verified the infected computer’s name before activating. Solar recommends that organizations go beyond basic antivirus deployment, emphasizing the importance of verifying digital signatures in trusted software directories and thoroughly investigating any antivirus alerts. Incident responders should actively search for additional tunnels, proxy chains, lateral movement tools, and any delayed destructive payloads. Crucially, security logs proved invaluable, preserving service creation events and traces of remote command execution, allowing investigators to reconstruct parts of the intrusion even after attackers had modified files and settings.

The following Indicators of Compromise (IoCs) are provided with their exact values from the source. It is important to note that while Solar’s narrative associates the substituted VMware library with Vasilek, its detailed indicator appendix identifies that particular sample as loading PartisanDNS. Both descriptions are included for accuracy; shared hosting addresses and legitimate artifacts necessitate careful contextual interpretation.

Indicators of Compromise (IoCs):-

Type Indicator Description
MD5 a6af32b1381d8985049e2d5ec1889bd9 PartisanDNS sample associated with the first listed system library.
MD5 338f7eafdfe45e93e57889ebd064d0d5 UPX-packed DNSCat2 sample appearing under two library paths.
MD5 39e64553b7ddf579240e6642042e6840 UPX-packed DNSCat2 sample.
MD5 a6ce67f063fce60954bb6cea4c969aac Additional PartisanDNS sample, including a backup copy.
MD5 1199d2f2b1a58435113555b02172bc79 UPX-packed DNSCat2 sample.
MD5 ccf73d3b1e9c625d79ce2c76650ca3e7 Custom loader-scheduler.
MD5 6b21d7574b53b753bfdc2acf9c389a90 3proxy sample occupying a VMware-themed executable path.
MD5 560397a1bfb7fc32f7eeb7794183993d Vasilek sample occupying the same executable path.
MD5 041a3ae432840507a755a79a22a1237a GOST sample in the VMware Tools directory.
MD5 2538be4331f69dbf4a9b79565fd39581 PartisanDNS executable.
MD5 f34430fb88bda6c904c57facab761fc2 GOST sample in the WSUS repository, deleted before examination.
MD5 86f330eb072216ffc807aff4013950f9 Substituted VMware library; appendix identifies it as loading PartisanDNS.
SHA-1 bdeac4b8e9a3c48661adf0c2ee5f05b58cee76eb PartisanDNS sample.
SHA-1 ed999aaaf1d032c76a51f4aececb99d06c371b33 UPX-packed DNSCat2 sample appearing under two library paths.
SHA-1 cd61f92873625dd25a31f414617347d1fa132747 UPX-packed DNSCat2 sample.
SHA-1 56df605a33fb77c91bdb92033efe983f336deb23 Additional PartisanDNS sample.
SHA-1 efe3503bd021de67e884878c6de1e8b110ed2ee7 UPX-packed DNSCat2 sample.
SHA-1 42f5cbbe0feba3e31ac8642791dd48eef8eae123 Custom loader-scheduler.
SHA-1 3b1424176c9c1083b79961783b38f5176ff99fee 3proxy sample.
SHA-1 3834c4c83cf9758385347a8b34a3e20e17aced3b Vasilek sample.
SHA-1 f2fb4a3ba5802df7ae83ac7fb362bce45223312b GOST sample in the VMware Tools directory.
SHA-1 d93f810fa02c3d4391810ab512519d89f2f0ceee PartisanDNS executable.
SHA-1 c4e623ab0a15db0896bf8a68eb9b45ebe6ae2f28 Unknown WSUS-themed file, deleted before investigation.
SHA-1 23831129ad88da40cd0bdeae2350f956ca0b2db2 GOST sample in the WSUS repository.
SHA-1 4335474d9fd48d7d28e244802e210f1e78dc2f3a Substituted VMware library.
SHA-256 cc8c707bf49c0cdb79b806d41df6254efc0e9f566a02d223871550f414469d13 PartisanDNS sample.
SHA-256 e5c6b6d37ff168def37dfd86c636e512be3ed7ead9a2dc93d5c741c42b47c1f1 UPX-packed DNSCat2 sample appearing under two library paths.
SHA-256 07381d79670129277211a4373e5518799a54b427946602539463ec2dd9cdb5e7 UPX-packed DNSCat2 sample.
SHA-256 4f0e23a83d83d901c76353d8b9b6ee2940eb63d531ad15f736193903b5c7c8c3 Additional PartisanDNS sample.
SHA-256 8c37c4b1f168219a1ce495c9822730981b20ff03d937ddcd8795fca14a9b7869 UPX-packed DNSCat2 sample.
SHA-256 5bc4fa9916c0883d45cb85639e328ed484dc75f4dfda294eb52f4b8b612889f2 Custom loader-scheduler.
SHA-256 c499fab59acbb1750e1e0e5a3c51d119ccd6374e5f0b45639f29598720222766 3proxy sample.
SHA-256 87e713f9b6ae14d97d3fa4d1a882c029e7e963d844d9c93ea383cab3d46a949c Vasilek sample.
SHA-256 d7aedc020ce832334abf0d03986da31f41cb2191355f25b17989dcfa8bb2775b GOST sample in the VMware Tools directory.
SHA-256 e55431d6f15aa78ada3f60ed30a3f32b444b952bdc53a652546c1820f8bfa513 PartisanDNS executable.
SHA-256 5076286c26f2a5c7dd7f507365fe404db2b05d39b350c463faa053baa37b3742 GOST sample in the WSUS repository.
SHA-256 125ead2c3b1d0f7aee03d13b927744ec8dc1d046912ce73efc9c5a10243b99dc Substituted VMware library.
IP address 172.67.210[.]25 Source-listed network indicator, labeled Cloudflare; shared infrastructure requires contextual assessment.
IP address 104.21.34[.]242 Source-listed network indicator, labeled Cloudflare; shared infrastructure requires contextual assessment.
IP address 199.59.243[.]228 Source-listed network indicator, labeled Amazon.
Domain okkgb[.]com Network indicator published by Solar.
Domain c-oh[.]com Network indicator published by Solar.
Domain 89e[.]org Network indicator published by Solar.
Domain parker-inc[.]com Network indicator published by Solar.
Domain c0ce[.]org DNSCat2 command-and-control domain detected in the incident.
Domain p7cp[.]org DNSCat2 command-and-control domain detected in the incident.
Domain gov-by[.]com Reused command-and-control domain overlapping earlier reporting.
Domain f91j[.]org DNSCat2 command-and-control domain detected in the incident.
Domain w3a01[.]net DNSCat2 command-and-control domain detected in the incident.
Historical domain 0ce[.]org Previously reported domain included for infrastructure comparison.
Historical domain 7cp[.]org Previously reported domain included for infrastructure comparison.
Historical domain 3a01[.]net Previously reported domain included for infrastructure comparison.
Historical domain 91j[.]org Previously reported domain included for infrastructure comparison.
DGA domain vpnosljjk[.]pro PartisanDNS domain-generation indicator.
DGA domain vfvnfaq[.]top PartisanDNS domain-generation indicator.
DGA domain vfvnfaq[.]link PartisanDNS domain-generation indicator.
DGA domain vfvnfaq[.]cyou PartisanDNS domain-generation indicator.
DGA domain vfvnfaq[.]pro PartisanDNS domain-generation indicator.
DGA domain vfvnfaq[.]me PartisanDNS domain-generation indicator.
DGA domain vfvnfaq[.]my PartisanDNS domain-generation indicator.
DGA domain vfvnfaq[.]buzz PartisanDNS domain-generation indicator.
DGA domain vfvnfaq[.]info PartisanDNS domain-generation indicator.
DGA domain vfvnfaq[.]space PartisanDNS domain-generation indicator.
DGA domain vfvnfaq[.]in PartisanDNS domain-generation indicator.
DGA domain vfvnfaq[.]sbs PartisanDNS domain-generation indicator.
DGA domain vfvnfaq[.]work PartisanDNS domain-generation indicator.
DGA domain vfvnfaq[.]casa PartisanDNS domain-generation indicator.
DGA domain vfvnfaq[.]lol PartisanDNS domain-generation indicator.
DGA domain vfvnfaq[.]lat PartisanDNS domain-generation indicator.
DGA domain vfvnfaq[.]net PartisanDNS domain-generation indicator.
DGA domain vfvnfaq[.]org PartisanDNS domain-generation indicator.
DGA domain vfvnfaq[.]com PartisanDNS domain-generation indicator.
File path C:WindowsSystem32msadcs32.dll PartisanDNS library; multiple samples occupied this path.
File path C:WindowsSystem32msadcs32.bak Backup-path copy of a PartisanDNS sample.
File path C:WindowsSystem32tpvmmon.dll DNSCat2 library launched through a Windows service.
File path C:Windowssystem32omega.dll Additional path for the same UPX-packed DNSCat2 sample.
File path C:WindowsSystem32aweman32.dll DNSCat2 library launched through a Windows service.
File path C:Windowssystem32uplay_r164.dll UPX-packed DNSCat2 library.
File path C:Program FilesVMwareVMware Toolsauthd.exe Custom loader-scheduler masquerading as a VMware component.
File path C:Program FilesVMwareVMware Toolsrpctool32.exe Path occupied by both 3proxy and Vasilek samples during the campaign.
File path C:Program FilesVMwareVMware Toolsvmtoolsd32.exe GOST executable with altered timestamps.
File path C:Windowsfstab.exe PartisanDNS executable.
File path C:Update169WSUSSCAN.exe Unknown file deleted before investigation.
File path E:WSUSUpdateServicesPackagesWsusService.exe GOST executable disguised as a WSUS component.
File path C:Program FilesVMwareVMware Toolsvmtools.dll Replaced VMware library; narrative links it to Vasilek, appendix says it loads PartisanDNS.
File path C:WindowsSystem32vmtoolsd.exe Executable associated with a service displayed as “VMware Service”; payload unspecified.
File path C:Program FilesVMwareVMware Toolsgost.yml GOST proxy configuration recovered in command-and-control exchanges.
File name vmtoolsd.dll Original legitimate VMware library renamed and retained, apparently for restoration.
File name vmtoolsd.exe Legitimate VMware component name imitated by attacker tooling; not independently malicious.
File name rpctool.exe Legitimate VMware component name imitated by attacker tooling; not independently malicious.
File name new.bak Downloaded replacement backdoor used during self-update.
File-name pattern old-<timestamp>.bak Previous backdoor executable renamed during self-update.
File-name notation old-.bak Source shorthand for the replaced backdoor backup.
File name MySong.mp3 Hardcoded audio filename referenced by an apparent developer debugging function.
File-name template [HOSTNAME]-tun.yml Telegram attachment filename shown in the recovered exchange.
File-name pattern C:Windows__<unix timestamp>.<microseconds> Remote command-output artifact consistent with Impacket execution.
UNC path pattern \127.0.0.1ADMIN$__<unix timestamp>.<microseconds> Remote command-output destination; loopback address is not external attacker infrastructure.
UNC path pattern \127.0.0.1ADMIN$__<ts>.<us> Alternate notation appearing in the source’s MITRE matrix.
Tool filename wmiexec.py Impacket tool associated with the observed command-output pattern; legitimate dual-use tool.
Executable name cmd.exe Windows command interpreter used in observed execution; not independently malicious.
Service name tpvmmon Malicious service displayed as “Windows Insiders Service.”
Service name aweman32 Malicious service displayed as “Windows Channels Service.”
Service name msadcs32 Malicious service displayed as “Sybase Inc. Product File.”
Service name uplay_r164 Malicious service displayed as “Access FT Imager Service.”
Service name vmauad Loader service displayed as “VMware Auth Adapter.”
Service artifact AppMgmt Legitimate Windows service whose parameters were apparently temporarily altered.
Registry path SOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystem Legitimate policy location inspected during privilege-elevation attempts.
Registry value ConsentPromptBehaviorAdmin UAC policy value checked by the backdoor; not independently malicious.
URL template https://api.telegram.org/bot<token>/<method> Legitimate Telegram API endpoint template assembled for command and control; token and method are placeholders.
Telegram chat ID -1002113172843 Group identifier visible in recovered command-and-control exchanges.
Telegram account name GroupAnonymousBot Legitimate Telegram identity used to post commands anonymously on behalf of the group.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM. Additional detailed indicators of compromise, including a comprehensive list of hashes, can be found in the <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/1af140e0-99ca-421b-b7bb-b5d18d5eb35f/Hackers-Hide-Vasilek-Backdoor-Inside-VMware-Tools-to-Target-Medical-Organizations.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Checksum-Mode=ENABLED&X-Amz-Credential=ASIA2F3EMEYETRCBKM73%2F20261007%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20261007T072557Z&X-Amz-Expires=1521&X-Amz-Security-Token=IQoJb3JpZ2luX2VjED8aCXVzLWVhc3QtMSJHMEUCICnHhPYHX%2FrqXPrlgAPkBOmEpksLDy3rrz21puwo%2Ff5RAiEA7ge2sSD8It5kctz4U%2FndxR7oHEvof7KZf4XD4tcWFJgqgAUIBxABGgw2OTk3NTMzMDk3MDUiDPeLTO9PAoZqXnS9LirdBMFl6S5dan39HMk2LbrkRyXUz3JUqnxFyW%2BvMHgonYWE3nEqn74yvvtTDvmWQPj8RL9sZWeJFpoxok%2FYHc2rW8vxWAMB3lgKgxUBroOh1PnJHSNiVAwGTI6T%2Ft84NE5BiqMyuuposJXITBX7jEXNwOpD2gbd3NO3HFP7N1yIO%2BEp9tEwy6khBWfxoM3a7MQ9pdPWXdta8cDh1xxpUsk5udUVu9%2BV5VnspoprHvMs1aD5n457xiVRVSIYwl7nGLIfqK8MaMR0kLZ9oeo6PHD%2BoUTGQGfpY95nXu5f99bO%2F0uHX%2BBm0FGq77BGDSnjJlj1XlxrBmQqAfcHVCZbF57gas5ev%2BvEfiYeX9M%2FPuyqgH%2FlyrXCs7uh%2BBlHqxbk4drU2k1yQBtFF3uRM%2BQwHJaXYTffPZdYWDz%2FMBkb%2FZd37hKlVFBLBmlWxR3Jbc%2F2dp4XjiOr4zKzS6VjohEGwJtJKEUW%2FaNdjN%2BOes%2FJBjObn2ywbsRORvOWnXfZxJA2ysH5aZvH%2B%2BGpos8pnL0M9eVDxBDW3SOPQhnm1uHC4MkLMJ2GOI1whX7zAGJoAwTGlxBWtHT0cjloSL%2F%2FbnK4S6F3rXAn7h%2BoQVA4jFRiMXbPOjD2aqevYqNuEHSU2NT%2BxOKJXZbQ%2BI2fUip010%2FGktujNZQkMP%2FuR4Bi1JsdkXSUkNm79byfVCYQQz%2Fqud9XbpKqeZm4qdIuV4HySGhVBdp%2BrXiQrS8pYdeFKDOZjXU7AUmU17WB%2FGgLf3CZrtYWDWgb0pGMJ0Tx3rs4jsqh4oqVKpEBWmdCgnSYHhe5V838MKPYl9YGOpgB8A8LsAy95Ix5pJRS%2BKFsl54cSoI7Ofr4l6ofAIiOz49dvUxOirWW5hQ26g3v7IoH9p4s2zi9A01JwDT2RK17k51GKFPQV3oP3iy8SNAedLvD5w2zABCP%2Bplou

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwarephishingSecurityThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Top 10 Best DAST Tools in 2026 [Ranked & Scored]

Next Post

Google Chrome Update Patches 247 Vulnerabilities, Including 4 Code Execution Flaws

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Google Chrome Update Patches 247 Vulnerabilities, Including 4 Code Execution Flaws
October 7, 2026
Critical VMware Tools Flaw Lets Attackers Install Vasilek Backdoor
October 7, 2026
Top 10 Best DAST Tools in 2026 [Ranked & Scored]
October 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us