Critical VMware Tools Flaw Lets Attackers Install Vasilek Backdoor
Key Takeaways A sophisticated threat actor has been observed embedding the Vasilek backdoor within legitimate VMware Tools installations. The attack chain targeted a medical organization, maintaining...
Key Takeaways
- A sophisticated threat actor has been observed embedding the Vasilek backdoor within legitimate VMware Tools installations.
- The attack chain targeted a medical organization, maintaining persistence for approximately two years and exposing sensitive data.
- The attackers leveraged trusted software directories and disguised malicious components with names mimicking genuine virtualization software.
- The Vasilek backdoor, controlled via Telegram, provides extensive surveillance and control capabilities, including command execution, file transfer, and keystroke logging.
- No specific vulnerability in VMware Tools was exploited; instead, the existing installation was abused as a stealthy hiding place.
Cybersecurity researchers have uncovered a persistent campaign where attackers integrated the Vasilek backdoor into a medical organization’s VMware Tools installation, maintaining covert access for around two years. This prolonged intrusion, dating back to early 2024, focused on espionage and data exfiltration rather than disruptive attacks, exploiting trust relationships with numerous affiliated medical institutions.
Table Of Content
Investigators from Solar 4RAYS, who initiated their probe in December 2025, identified an updated variant of Vasilek and a previously unknown custom loader. Evidence points to initial remote command execution, followed by lateral movement using legitimate remote desktop and Windows file-sharing services. While the initial compromise vector remains unconfirmed, Solar’s analysis, detailed in a report shared with Cyber Security News (CSN), suggests a link to the threat group known as Partisan Zmiy due to overlapping infrastructure and tactics.
The attackers exploited the organization’s extensive network of subsidiary medical institutions, likely using this access for intelligence gathering across connected entities. This incident underscores a growing trend of threat actors camouflaging malicious activities within common software and network services, particularly when targeting the healthcare sector.
Stealthy Integration within VMware Tools
The attackers did not exploit a vulnerability within VMware Tools itself. Instead, they leveraged an existing, legitimate installation of VMware Tools that was present but unused by administrators. This provided a trusted, yet unmonitored, location to deploy their malicious components. These components were deliberately named to resemble authentic virtualization software, further aiding their concealment.
Before their discovery in December 2025, the attackers replaced a legitimate VMware library with their malicious code, carefully preserving the original file under a different name—a tactic likely intended for potential restoration or to avoid immediate detection. Unlike the genuine library, the substituted malicious file lacked a digital signature. Solar described this library substitution as a key mechanism for maintaining persistent access.
This method of hiding malware within familiar software directories is consistent with other backdoor research, highlighting a broader adversary trend of blending into the legitimate operational environment. Furthermore, the attackers created Windows services with innocuous display names, ensuring their malicious libraries and custom loader appeared as routine entries in service listings.
The custom loader was configured to execute its tools on a fixed schedule. For instance, a GOST tunnel activated every Saturday evening from 10 p.m. to 11 p.m., while another tunnel and the Vasilek backdoor launched once, eight hours after the service started. Researchers interpret this limited operational window as a potential backup communication channel. Further evidence of concealment included the alteration of file timestamps to match legitimate VMware components and the reuse of file paths for different malicious tools. The loader’s configuration also referenced a server-specific Windows update repository, indicating that deployment followed meticulous reconnaissance rather than generic settings.
Vasilek Backdoor: Telegram Control and Detection Challenges
Vasilek, a 32-bit Windows backdoor first publicly documented in 2025, was analyzed by Solar in version 1.5.8. This variant features a comprehensive command table with 59 entries, including aliases, enabling a wide array of malicious actions. Its capabilities encompass remote command execution, file transfers, keystroke logging, screenshot capture, clipboard content collection, and mouse input manipulation.
Operators controlled Vasilek through a Telegram group, utilizing the public Bot API. They posted commands anonymously on behalf of the group, and the malware returned results to the same chat, further obscuring their identities. The backdoor’s connections were routed through corporate proxy settings, allowing them to blend with legitimate network traffic.
Telegram was not the sole command-and-control channel. The attackers also employed DNSCat2, PartisanDNS, and a GOST-plus-3proxy chain, ensuring multiple redundant access points. This multi-channel approach means blocking a single service would be insufficient to disrupt their operations. The use of DNS tunneling for C2 traffic highlights how attackers can hide malicious communications within ordinary network activity, though these campaigns are not necessarily linked.
To thwart analysis, the Vasilek backdoor verified the infected computer’s name before activating. Solar recommends that organizations go beyond basic antivirus deployment, emphasizing the importance of verifying digital signatures in trusted software directories and thoroughly investigating any antivirus alerts. Incident responders should actively search for additional tunnels, proxy chains, lateral movement tools, and any delayed destructive payloads. Crucially, security logs proved invaluable, preserving service creation events and traces of remote command execution, allowing investigators to reconstruct parts of the intrusion even after attackers had modified files and settings.
The following Indicators of Compromise (IoCs) are provided with their exact values from the source. It is important to note that while Solar’s narrative associates the substituted VMware library with Vasilek, its detailed indicator appendix identifies that particular sample as loading PartisanDNS. Both descriptions are included for accuracy; shared hosting addresses and legitimate artifacts necessitate careful contextual interpretation.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| MD5 | a6af32b1381d8985049e2d5ec1889bd9 |
PartisanDNS sample associated with the first listed system library. |
| MD5 | 338f7eafdfe45e93e57889ebd064d0d5 |
UPX-packed DNSCat2 sample appearing under two library paths. |
| MD5 | 39e64553b7ddf579240e6642042e6840 |
UPX-packed DNSCat2 sample. |
| MD5 | a6ce67f063fce60954bb6cea4c969aac |
Additional PartisanDNS sample, including a backup copy. |
| MD5 | 1199d2f2b1a58435113555b02172bc79 |
UPX-packed DNSCat2 sample. |
| MD5 | ccf73d3b1e9c625d79ce2c76650ca3e7 |
Custom loader-scheduler. |
| MD5 | 6b21d7574b53b753bfdc2acf9c389a90 |
3proxy sample occupying a VMware-themed executable path. |
| MD5 | 560397a1bfb7fc32f7eeb7794183993d |
Vasilek sample occupying the same executable path. |
| MD5 | 041a3ae432840507a755a79a22a1237a |
GOST sample in the VMware Tools directory. |
| MD5 | 2538be4331f69dbf4a9b79565fd39581 |
PartisanDNS executable. |
| MD5 | f34430fb88bda6c904c57facab761fc2 |
GOST sample in the WSUS repository, deleted before examination. |
| MD5 | 86f330eb072216ffc807aff4013950f9 |
Substituted VMware library; appendix identifies it as loading PartisanDNS. |
| SHA-1 | bdeac4b8e9a3c48661adf0c2ee5f05b58cee76eb |
PartisanDNS sample. |
| SHA-1 | ed999aaaf1d032c76a51f4aececb99d06c371b33 |
UPX-packed DNSCat2 sample appearing under two library paths. |
| SHA-1 | cd61f92873625dd25a31f414617347d1fa132747 |
UPX-packed DNSCat2 sample. |
| SHA-1 | 56df605a33fb77c91bdb92033efe983f336deb23 |
Additional PartisanDNS sample. |
| SHA-1 | efe3503bd021de67e884878c6de1e8b110ed2ee7 |
UPX-packed DNSCat2 sample. |
| SHA-1 | 42f5cbbe0feba3e31ac8642791dd48eef8eae123 |
Custom loader-scheduler. |
| SHA-1 | 3b1424176c9c1083b79961783b38f5176ff99fee |
3proxy sample. |
| SHA-1 | 3834c4c83cf9758385347a8b34a3e20e17aced3b |
Vasilek sample. |
| SHA-1 | f2fb4a3ba5802df7ae83ac7fb362bce45223312b |
GOST sample in the VMware Tools directory. |
| SHA-1 | d93f810fa02c3d4391810ab512519d89f2f0ceee |
PartisanDNS executable. |
| SHA-1 | c4e623ab0a15db0896bf8a68eb9b45ebe6ae2f28 |
Unknown WSUS-themed file, deleted before investigation. |
| SHA-1 | 23831129ad88da40cd0bdeae2350f956ca0b2db2 |
GOST sample in the WSUS repository. |
| SHA-1 | 4335474d9fd48d7d28e244802e210f1e78dc2f3a |
Substituted VMware library. |
| SHA-256 | cc8c707bf49c0cdb79b806d41df6254efc0e9f566a02d223871550f414469d13 |
PartisanDNS sample. |
| SHA-256 | e5c6b6d37ff168def37dfd86c636e512be3ed7ead9a2dc93d5c741c42b47c1f1 |
UPX-packed DNSCat2 sample appearing under two library paths. |
| SHA-256 | 07381d79670129277211a4373e5518799a54b427946602539463ec2dd9cdb5e7 |
UPX-packed DNSCat2 sample. |
| SHA-256 | 4f0e23a83d83d901c76353d8b9b6ee2940eb63d531ad15f736193903b5c7c8c3 |
Additional PartisanDNS sample. |
| SHA-256 | 8c37c4b1f168219a1ce495c9822730981b20ff03d937ddcd8795fca14a9b7869 |
UPX-packed DNSCat2 sample. |
| SHA-256 | 5bc4fa9916c0883d45cb85639e328ed484dc75f4dfda294eb52f4b8b612889f2 |
Custom loader-scheduler. |
| SHA-256 | c499fab59acbb1750e1e0e5a3c51d119ccd6374e5f0b45639f29598720222766 |
3proxy sample. |
| SHA-256 | 87e713f9b6ae14d97d3fa4d1a882c029e7e963d844d9c93ea383cab3d46a949c |
Vasilek sample. |
| SHA-256 | d7aedc020ce832334abf0d03986da31f41cb2191355f25b17989dcfa8bb2775b |
GOST sample in the VMware Tools directory. |
| SHA-256 | e55431d6f15aa78ada3f60ed30a3f32b444b952bdc53a652546c1820f8bfa513 |
PartisanDNS executable. |
| SHA-256 | 5076286c26f2a5c7dd7f507365fe404db2b05d39b350c463faa053baa37b3742 |
GOST sample in the WSUS repository. |
| SHA-256 | 125ead2c3b1d0f7aee03d13b927744ec8dc1d046912ce73efc9c5a10243b99dc |
Substituted VMware library. |
| IP address | 172.67.210[.]25 |
Source-listed network indicator, labeled Cloudflare; shared infrastructure requires contextual assessment. |
| IP address | 104.21.34[.]242 |
Source-listed network indicator, labeled Cloudflare; shared infrastructure requires contextual assessment. |
| IP address | 199.59.243[.]228 |
Source-listed network indicator, labeled Amazon. |
| Domain | okkgb[.]com |
Network indicator published by Solar. |
| Domain | c-oh[.]com |
Network indicator published by Solar. |
| Domain | 89e[.]org |
Network indicator published by Solar. |
| Domain | parker-inc[.]com |
Network indicator published by Solar. |
| Domain | c0ce[.]org |
DNSCat2 command-and-control domain detected in the incident. |
| Domain | p7cp[.]org |
DNSCat2 command-and-control domain detected in the incident. |
| Domain | gov-by[.]com |
Reused command-and-control domain overlapping earlier reporting. |
| Domain | f91j[.]org |
DNSCat2 command-and-control domain detected in the incident. |
| Domain | w3a01[.]net |
DNSCat2 command-and-control domain detected in the incident. |
| Historical domain | 0ce[.]org |
Previously reported domain included for infrastructure comparison. |
| Historical domain | 7cp[.]org |
Previously reported domain included for infrastructure comparison. |
| Historical domain | 3a01[.]net |
Previously reported domain included for infrastructure comparison. |
| Historical domain | 91j[.]org |
Previously reported domain included for infrastructure comparison. |
| DGA domain | vpnosljjk[.]pro |
PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]top |
PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]link |
PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]cyou |
PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]pro |
PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]me |
PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]my |
PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]buzz |
PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]info |
PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]space |
PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]in |
PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]sbs |
PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]work |
PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]casa |
PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]lol |
PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]lat |
PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]net |
PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]org |
PartisanDNS domain-generation indicator. |
| DGA domain | vfvnfaq[.]com |
PartisanDNS domain-generation indicator. |
| File path | C:WindowsSystem32msadcs32.dll |
PartisanDNS library; multiple samples occupied this path. |
| File path | C:WindowsSystem32msadcs32.bak |
Backup-path copy of a PartisanDNS sample. |
| File path | C:WindowsSystem32tpvmmon.dll |
DNSCat2 library launched through a Windows service. |
| File path | C:Windowssystem32omega.dll |
Additional path for the same UPX-packed DNSCat2 sample. |
| File path | C:WindowsSystem32aweman32.dll |
DNSCat2 library launched through a Windows service. |
| File path | C:Windowssystem32uplay_r164.dll |
UPX-packed DNSCat2 library. |
| File path | C:Program FilesVMwareVMware Toolsauthd.exe |
Custom loader-scheduler masquerading as a VMware component. |
| File path | C:Program FilesVMwareVMware Toolsrpctool32.exe |
Path occupied by both 3proxy and Vasilek samples during the campaign. |
| File path | C:Program FilesVMwareVMware Toolsvmtoolsd32.exe |
GOST executable with altered timestamps. |
| File path | C:Windowsfstab.exe |
PartisanDNS executable. |
| File path | C:Update169WSUSSCAN.exe |
Unknown file deleted before investigation. |
| File path | E:WSUSUpdateServicesPackagesWsusService.exe |
GOST executable disguised as a WSUS component. |
| File path | C:Program FilesVMwareVMware Toolsvmtools.dll |
Replaced VMware library; narrative links it to Vasilek, appendix says it loads PartisanDNS. |
| File path | C:WindowsSystem32vmtoolsd.exe |
Executable associated with a service displayed as “VMware Service”; payload unspecified. |
| File path | C:Program FilesVMwareVMware Toolsgost.yml |
GOST proxy configuration recovered in command-and-control exchanges. |
| File name | vmtoolsd.dll |
Original legitimate VMware library renamed and retained, apparently for restoration. |
| File name | vmtoolsd.exe |
Legitimate VMware component name imitated by attacker tooling; not independently malicious. |
| File name | rpctool.exe |
Legitimate VMware component name imitated by attacker tooling; not independently malicious. |
| File name | new.bak |
Downloaded replacement backdoor used during self-update. |
| File-name pattern | old-<timestamp>.bak |
Previous backdoor executable renamed during self-update. |
| File-name notation | old-.bak |
Source shorthand for the replaced backdoor backup. |
| File name | MySong.mp3 |
Hardcoded audio filename referenced by an apparent developer debugging function. |
| File-name template | [HOSTNAME]-tun.yml |
Telegram attachment filename shown in the recovered exchange. |
| File-name pattern | C:Windows__<unix timestamp>.<microseconds> |
Remote command-output artifact consistent with Impacket execution. |
| UNC path pattern | \127.0.0.1ADMIN$__<unix timestamp>.<microseconds> |
Remote command-output destination; loopback address is not external attacker infrastructure. |
| UNC path pattern | \127.0.0.1ADMIN$__<ts>.<us> |
Alternate notation appearing in the source’s MITRE matrix. |
| Tool filename | wmiexec.py |
Impacket tool associated with the observed command-output pattern; legitimate dual-use tool. |
| Executable name | cmd.exe |
Windows command interpreter used in observed execution; not independently malicious. |
| Service name | tpvmmon |
Malicious service displayed as “Windows Insiders Service.” |
| Service name | aweman32 |
Malicious service displayed as “Windows Channels Service.” |
| Service name | msadcs32 |
Malicious service displayed as “Sybase Inc. Product File.” |
| Service name | uplay_r164 |
Malicious service displayed as “Access FT Imager Service.” |
| Service name | vmauad |
Loader service displayed as “VMware Auth Adapter.” |
| Service artifact | AppMgmt |
Legitimate Windows service whose parameters were apparently temporarily altered. |
| Registry path | SOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystem |
Legitimate policy location inspected during privilege-elevation attempts. |
| Registry value | ConsentPromptBehaviorAdmin |
UAC policy value checked by the backdoor; not independently malicious. |
| URL template | https://api.telegram.org/bot<token>/<method> |
Legitimate Telegram API endpoint template assembled for command and control; token and method are placeholders. |
| Telegram chat ID | -1002113172843 |
Group identifier visible in recovered command-and-control exchanges. |
| Telegram account name | GroupAnonymousBot |
Legitimate Telegram identity used to post commands anonymously on behalf of the group. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM. Additional detailed indicators of compromise, including a comprehensive list of hashes, can be found in the <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/1af140e0-99ca-421b-b7bb-b5d18d5eb35f/Hackers-Hide-Vasilek-Backdoor-Inside-VMware-Tools-to-Target-Medical-Organizations.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Checksum-Mode=ENABLED&X-Amz-Credential=ASIA2F3EMEYETRCBKM73%2F20261007%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20261007T072557Z&X-Amz-Expires=1521&X-Amz-Security-Token=IQoJb3JpZ2luX2VjED8aCXVzLWVhc3QtMSJHMEUCICnHhPYHX%2FrqXPrlgAPkBOmEpksLDy3rrz21puwo%2Ff5RAiEA7ge2sSD8It5kctz4U%2FndxR7oHEvof7KZf4XD4tcWFJgqgAUIBxABGgw2OTk3NTMzMDk3MDUiDPeLTO9PAoZqXnS9LirdBMFl6S5dan39HMk2LbrkRyXUz3JUqnxFyW%2BvMHgonYWE3nEqn74yvvtTDvmWQPj8RL9sZWeJFpoxok%2FYHc2rW8vxWAMB3lgKgxUBroOh1PnJHSNiVAwGTI6T%2Ft84NE5BiqMyuuposJXITBX7jEXNwOpD2gbd3NO3HFP7N1yIO%2BEp9tEwy6khBWfxoM3a7MQ9pdPWXdta8cDh1xxpUsk5udUVu9%2BV5VnspoprHvMs1aD5n457xiVRVSIYwl7nGLIfqK8MaMR0kLZ9oeo6PHD%2BoUTGQGfpY95nXu5f99bO%2F0uHX%2BBm0FGq77BGDSnjJlj1XlxrBmQqAfcHVCZbF57gas5ev%2BvEfiYeX9M%2FPuyqgH%2FlyrXCs7uh%2BBlHqxbk4drU2k1yQBtFF3uRM%2BQwHJaXYTffPZdYWDz%2FMBkb%2FZd37hKlVFBLBmlWxR3Jbc%2F2dp4XjiOr4zKzS6VjohEGwJtJKEUW%2FaNdjN%2BOes%2FJBjObn2ywbsRORvOWnXfZxJA2ysH5aZvH%2B%2BGpos8pnL0M9eVDxBDW3SOPQhnm1uHC4MkLMJ2GOI1whX7zAGJoAwTGlxBWtHT0cjloSL%2F%2FbnK4S6F3rXAn7h%2BoQVA4jFRiMXbPOjD2aqevYqNuEHSU2NT%2BxOKJXZbQ%2BI2fUip010%2FGktujNZQkMP%2FuR4Bi1JsdkXSUkNm79byfVCYQQz%2Fqud9XbpKqeZm4qdIuV4HySGhVBdp%2BrXiQrS8pYdeFKDOZjXU7AUmU17WB%2FGgLf3CZrtYWDWgb0pGMJ0Tx3rs4jsqh4oqVKpEBWmdCgnSYHhe5V838MKPYl9YGOpgB8A8LsAy95Ix5pJRS%2BKFsl54cSoI7Ofr4l6ofAIiOz49dvUxOirWW5hQ26g3v7IoH9p4s2zi9A01JwDT2RK17k51GKFPQV3oP3iy8SNAedLvD5w2zABCP%2Bplou
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.