Telegram-Linked Malware Exploits DNS Tunneling in Extended Attack on Healthcare Provider
Cybersecurity investigators disclosed a months‑long intrusion of a medical organization by the Partisan Zmiy threat group, revealing a sophisticated malware toolkit that leverages Telegram messaging for command‑and‑control, DNS tunneling for data exfiltration, and timed payload execution to evade detection.
The investigation, which began in December 2025, traced the earliest indicators of compromise to early 2025. Analysts observed that the attackers established a persistent foothold by embedding a custom backdoor within the network’s internal systems. The backdoor communicated with operators through a Telegram bot, a channel that provides encrypted, low‑latency messaging and is difficult for traditional network monitoring tools to flag.
In parallel, the malware employed DNS tunneling to disguise outbound traffic as legitimate DNS queries. By encoding data within DNS request packets, the actors could move information out of the network without triggering standard firewall alerts. This dual‑channel approach—Telegram for commands and DNS for exfiltration—allowed the campaign to maintain operational flexibility while reducing its footprint.
The toolkit also featured a scheduler that activated secondary payloads at pre‑determined intervals. This capability enabled the attackers to stagger malicious activity, complicating forensic timelines and prolonging the intrusion. Security teams noted that the scheduled tasks were designed to align with off‑peak hospital hours, minimizing the likelihood of immediate detection by staff or automated defenses.
Experts say the incident underscores the growing attractiveness of the healthcare sector to sophisticated actors, given the sector’s reliance on legacy systems and the high value of patient data. The use of widely available platforms such as Telegram for command‑and‑control highlights a shift toward “living‑off‑the‑land” techniques that blend legitimate services with malicious intent. Investigators continue to monitor the network for residual artifacts and are advising similar organizations to audit their DNS traffic, restrict external messaging applications, and implement multi‑factor authentication for any remote access channels.
Comments (0)
Be the first to comment.
Join the discussion