Skip to content
July 27, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Cybercriminals
  • VMRay Exposes Operation STANDOFF, a Russian-Speaking Intrusion Campaign Hidden Behind GitHub
  • Cybercriminals

VMRay Exposes Operation STANDOFF, a Russian-Speaking Intrusion Campaign Hidden Behind GitHub

Do Son July 27, 2026 5 minutes read
0
Operation STANDOFF infrastructure map showing a Russian-speaking threat group hiding C2 servers behind GitHub redirects

MITRE ATT&CK techniques | Image: VMRay

Add Daily CyberSecurity as a preferred source on Google

At a glance

Actor or group Unnamed Russian-speaking crew tracked as Operation STANDOFF; self-branded “GG Influence” and “ggstandoff”
Activity type Pay-per-install malware, proxy-botnet, hands-on-keyboard intrusion, AI-driven influence
Targets or victims Russian-speaking mobile gamers; corporate Active Directory networks
Scale 44 suspected C2 servers, down from 48; no victim count or financial loss confirmed
Jurisdiction or law-enforcement status No arrests or charges announced; infrastructure still active
Source VMRay Labs execution-level analysis, plus public research on the same malware families

TL;DR

A single malware detection led VMRay Labs to a full criminal operation. Operation STANDOFF fuses commodity stealers, a proxy-botnet, a custom intrusion console and an AI-run influence platform. Every layer sits on the same Russian hosting, and every layer hides behind redirects to GitHub.

What happened

The trail started with one file: setup_x86_x64_install.exe, a 16.65 MB NSIS installer. VMRay detonated it on 13 May 2026. The run spawned 152 processes and matched 70 threat identifier rules with 479 hits.

The sample is a pay-per-install loader. It writes roughly 40 to 50 executables into a temporary staging folder, then fires them off one by one. The bundle carries Raccoon Stealer v1.7.2, RedLine, Amadey, SmokeLoader, Socelars, Glupteba and the XMRig Monero miner.

That payload mix is not new. Bitsight researchers documented the same families moving through the PrivateLoader distribution service years earlier. Operation STANDOFF simply wires the old crimeware bundle into something much larger.

Security tools go down first

Before stealing anything, the loader clears the ground. PowerShell commands switch off Defender real-time monitoring, block sample submission and add the staging folder as a scan exclusion. The bundle also hunts for eleven security products, then stops or deletes the Windows Update service.

Persistence follows quickly. One component drops a fake csrss.exe under C:\Windows\rss\ and registers it at startup. It then installs services with VirtualBox-style names, opens local TCP listeners and adds its own firewall rule.

The GitHub disguise

Two addresses matter most. A child process fetches /server.txt from 212.193.30[.]29 and /proxies.txt from 212.193.30[.]45. Both sit on Russian provider TimeWeb Ltd. (AS9123).

The proxy host answers unsolicited scans with a 301 redirect to github.com. As a result, the report notes, the machine “appears to be a benign redirector toward a trusted domain”. VMRay stresses that GitHub itself is neither compromised nor complicit.

Defenders still get a gift. The malware builds a broken User-Agent string that reaches the wire as a single control byte. That flaw makes a strong network signature.

Who is behind it

VMRay assesses with high confidence that Russian speakers run the campaign. Operator tooling is written in Russian, schedules run on Moscow time, and the same branding repeats across domains. Investigators say they also linked the operation to one individual, yet they withheld that identity from the report.

No arrests, charges or indictments have been announced anywhere. Nobody has been convicted, and the suspected operators remain unnamed in public.

Inside the STANDOFF COORD console

Server 212.193.30[.]29 serves a login panel branded “STANDOFF COORD” under the domain russianhackers[.]online. The execution-level analysis of Operation STANDOFF published by VMRay Labs describes a multi-tenant platform closer to a red-team product than a commodity malware panel.

The credential vault accepts passwords, NTLM hashes, Kerberos tickets, API tokens, cookies and private keys. Hosts carry internal, external or dmz labels. Operators earn points once a target reaches the confirmed_exploit state.

Placeholder text reads like a training manual. One example tells an operator to log that they “got SYSTEM on dc01 via PrintNightmare”, the 2021 print spooler flaw tracked as CVE-2021-34527.

Impact and scale

Pivoting on the redirect trick exposed 48 related servers. That set has since shrunk to 44, all published as indicators of compromise.

A second host, 217.198.13[.]211, carries the influence machinery. One application farms Telegram accounts across fourteen modules, covering login codes, proxy rotation and reputation warming. Notably, it draws proxies from the very pool that infected victims feed.

A visual dialog builder then drives those accounts. A GPT node writes comments and replies in the voice of a persona with a set name, age, style and goal. A separate platform automates outreach across email, Telegram and WhatsApp.

The public face is a Russian gaming portal for Standoff 2 and PUBG Mobile. It promises free skins and promo codes, then links out to loot-box gambling sites. VMRay assesses that this young audience forms the main victim pool.

No confirmed victim count exists yet. The report publishes no revenue figures either, so any profit estimate would be guesswork.

What comes next

Much of this infrastructure stays online and undetected by security vendors. Defenders should therefore act on the published indicators now, rather than wait for a takedown.

Practical steps for defenders

  • Block the listed TimeWeb IP addresses and the actor-controlled domains.
  • Alert on HTTP requests carrying malformed or single-byte User-Agent headers.
  • Watch for new Defender exclusions and disabled real-time protection.
  • Hunt for VirtualBox-named services on hosts that run no virtualization.
  • Patch PrintNightmare and audit Active Directory service accounts.
  • Rotate credentials after any stealer infection, including cookies and Kerberos tickets.

One broader lesson stands out. Crimeware, targeted intrusion and information operations now share a single roof, a single toolchain and a single team.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.


We respect your inbox. Unsubscribe anytime.

Related coverage

  • Inside “HexagonalRodent”: The AI-Powered DPRK Syndicate Hauling Millions in Crypto
  • AI Tools Turn Trojan: Fake Video Platforms Drop Noodlophile Stealer and XWorm Payloads
  • The “Special Invitation” Trap: STAC6405 Abuses Legitimate RMM Tools to Hijack Your PC
  • Cloudflare Mitigates Record 7.3 Tbps DDoS Attack: 37.4 TB in 45 Seconds
  • The AI Double-Edged Sword: How Generative AI Is Fueling a New Wave of Cyberattacks
Track all actively exploited CVEs →

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: active directory Operation STANDOFF proxy botnet Raccoon Stealer Russian-speaking threat group Telegram account farm VMRay

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16812CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intel📅 Updated: Jul 27, 2026
  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2021-27137CVSS 8.1
    An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality...
    CISA KEV📅 Added to KEV: Jul 21, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-59550CVSS 9.3
    Unauthenticated SQL Injection in AWP Classifieds
  • CVE-2026-59549CVSS 9.3
    Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress
  • CVE-2026-59538CVSS 9.3
    Unauthenticated SQL Injection in GamiPress
  • CVE-2026-59533CVSS 9.3
    Unauthenticated SQL Injection in Relevanssi Light
  • CVE-2026-59527CVSS 9.3
    Unauthenticated SQL Injection in MapSVG
  • CVE-2026-61511CVSS 9.8
    vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection...
  • CVE-2026-64530CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api:...
  • CVE-2026-66013CVSS 9.3
    OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration...
  • CVE-2026-66012CVSS 10.0
    SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp...
  • CVE-2026-64523CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: net/handshake: Take...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.