Skip to content
September 29, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Cybercriminals
  • VMRay Exposes Operation STANDOFF, a Russian-Speaking Intrusion Campaign Hidden Behind GitHub
  • Cybercriminals

VMRay Exposes Operation STANDOFF, a Russian-Speaking Intrusion Campaign Hidden Behind GitHub

Do Son July 27, 2026 5 minutes read
0
Operation STANDOFF infrastructure map showing a Russian-speaking threat group hiding C2 servers behind GitHub redirects

MITRE ATT&CK techniques | Image: VMRay

Add Daily CyberSecurity as a preferred source on Google

At a glance

Actor or group Unnamed Russian-speaking crew tracked as Operation STANDOFF; self-branded “GG Influence” and “ggstandoff”
Activity type Pay-per-install malware, proxy-botnet, hands-on-keyboard intrusion, AI-driven influence
Targets or victims Russian-speaking mobile gamers; corporate Active Directory networks
Scale 44 suspected C2 servers, down from 48; no victim count or financial loss confirmed
Jurisdiction or law-enforcement status No arrests or charges announced; infrastructure still active
Source VMRay Labs execution-level analysis, plus public research on the same malware families

TL;DR

A single malware detection led VMRay Labs to a full criminal operation. Operation STANDOFF fuses commodity stealers, a proxy-botnet, a custom intrusion console and an AI-run influence platform. Every layer sits on the same Russian hosting, and every layer hides behind redirects to GitHub.

What happened

The trail started with one file: setup_x86_x64_install.exe, a 16.65 MB NSIS installer. VMRay detonated it on 13 May 2026. The run spawned 152 processes and matched 70 threat identifier rules with 479 hits.

The sample is a pay-per-install loader. It writes roughly 40 to 50 executables into a temporary staging folder, then fires them off one by one. The bundle carries Raccoon Stealer v1.7.2, RedLine, Amadey, SmokeLoader, Socelars, Glupteba and the XMRig Monero miner.

That payload mix is not new. Bitsight researchers documented the same families moving through the PrivateLoader distribution service years earlier. Operation STANDOFF simply wires the old crimeware bundle into something much larger.

Security tools go down first

Before stealing anything, the loader clears the ground. PowerShell commands switch off Defender real-time monitoring, block sample submission and add the staging folder as a scan exclusion. The bundle also hunts for eleven security products, then stops or deletes the Windows Update service.

Persistence follows quickly. One component drops a fake csrss.exe under C:\Windows\rss\ and registers it at startup. It then installs services with VirtualBox-style names, opens local TCP listeners and adds its own firewall rule.

The GitHub disguise

Two addresses matter most. A child process fetches /server.txt from 212.193.30[.]29 and /proxies.txt from 212.193.30[.]45. Both sit on Russian provider TimeWeb Ltd. (AS9123).

The proxy host answers unsolicited scans with a 301 redirect to github.com. As a result, the report notes, the machine “appears to be a benign redirector toward a trusted domain”. VMRay stresses that GitHub itself is neither compromised nor complicit.

Defenders still get a gift. The malware builds a broken User-Agent string that reaches the wire as a single control byte. That flaw makes a strong network signature.

Who is behind it

VMRay assesses with high confidence that Russian speakers run the campaign. Operator tooling is written in Russian, schedules run on Moscow time, and the same branding repeats across domains. Investigators say they also linked the operation to one individual, yet they withheld that identity from the report.

No arrests, charges or indictments have been announced anywhere. Nobody has been convicted, and the suspected operators remain unnamed in public.

Inside the STANDOFF COORD console

Server 212.193.30[.]29 serves a login panel branded “STANDOFF COORD” under the domain russianhackers[.]online. The execution-level analysis of Operation STANDOFF published by VMRay Labs describes a multi-tenant platform closer to a red-team product than a commodity malware panel.

The credential vault accepts passwords, NTLM hashes, Kerberos tickets, API tokens, cookies and private keys. Hosts carry internal, external or dmz labels. Operators earn points once a target reaches the confirmed_exploit state.

Placeholder text reads like a training manual. One example tells an operator to log that they “got SYSTEM on dc01 via PrintNightmare”, the 2021 print spooler flaw tracked as CVE-2021-34527.

Impact and scale

Pivoting on the redirect trick exposed 48 related servers. That set has since shrunk to 44, all published as indicators of compromise.

A second host, 217.198.13[.]211, carries the influence machinery. One application farms Telegram accounts across fourteen modules, covering login codes, proxy rotation and reputation warming. Notably, it draws proxies from the very pool that infected victims feed.

A visual dialog builder then drives those accounts. A GPT node writes comments and replies in the voice of a persona with a set name, age, style and goal. A separate platform automates outreach across email, Telegram and WhatsApp.

The public face is a Russian gaming portal for Standoff 2 and PUBG Mobile. It promises free skins and promo codes, then links out to loot-box gambling sites. VMRay assesses that this young audience forms the main victim pool.

No confirmed victim count exists yet. The report publishes no revenue figures either, so any profit estimate would be guesswork.

What comes next

Much of this infrastructure stays online and undetected by security vendors. Defenders should therefore act on the published indicators now, rather than wait for a takedown.

Practical steps for defenders

  • Block the listed TimeWeb IP addresses and the actor-controlled domains.
  • Alert on HTTP requests carrying malformed or single-byte User-Agent headers.
  • Watch for new Defender exclusions and disabled real-time protection.
  • Hunt for VirtualBox-named services on hosts that run no virtualization.
  • Patch PrintNightmare and audit Active Directory service accounts.
  • Rotate credentials after any stealer infection, including cookies and Kerberos tickets.

One broader lesson stands out. Crimeware, targeted intrusion and information operations now share a single roof, a single toolchain and a single team.

Related coverage

  • Weaponized JPEG Payload Deploys Trojanized ScreenConnect for Covert Espionage
  • The Internet Rewired: Cloudflare 2025 Review Unveils the AI Bot War and a 19% Traffic Surge
  • The Payroll Pirate Campaign Leverages AiTM Session Hijacking to Target HR Departments
  • Kimsuky HttpSpy Malware Campaign Exploits Networks via Deceptive Overlays
  • Australia Joins US, Slaps Sanctions on North Korean Cybercriminals for Funding WMD Programs
  • Operation Hanoi Thief: Hackers Use ‘Pseudo-Polyglot’ LNK/Image to Deploy LOTUSHARVEST Stealer via DLL Sideloading
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: active directory Operation STANDOFF proxy botnet Raccoon Stealer Russian-speaking threat group Telegram account farm VMRay

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intel📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 23, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-102361CVSS 9.3
    mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101264CVSS 9.4
    A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork/set_passwd....
    📅 Updated: Sep 28, 2026
  • CVE-2026-13214CVSS 9.8
    The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). When handling a GetConfiguration request...
    📅 Updated: Sep 28, 2026
  • CVE-2026-49845CVSS 9.8
    SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows...
    📅 Updated: Sep 28, 2026
  • CVE-2026-55976CVSS 9.1
    Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated remote...
    📅 Updated: Sep 28, 2026
  • CVE-2026-90048CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() ni_create_attr_list() allocates...
    📅 Updated: Sep 28, 2026
  • CVE-2026-90049CVSS 9.3
    In the Linux kernel, the following vulnerability has been resolved: net: skbuff: don't skb_tx_error() the source skb in...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101263CVSS 9.4
    A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file...
    📅 Updated: Sep 28, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.