Operation STANDOFF is a Russian-speaking cybercrime campaign that turns a single infection into a wider compromise.
Its installer delivers information stealers, loaders, a cryptocurrency miner, and botnet components, while operators can later focus on selected victims for direct network intrusion.
The campaign also uses gaming-themed content and automated outreach to draw people toward its malware delivery ecosystem.
The operation relies on a pay-per-install model that bundles several malware families into one package.
The observed sample installed RedLine, Raccoon Stealer, Amadey, SmokeLoader, Socelars, Glupteba, and XMRig, allowing the attackers to steal credentials, mine cryptocurrency, and retain access to infected systems.
Researchers at VMRay identified the activity after linking behavior that initially appeared unrelated, including dropped files, unusual network requests, and shared server infrastructure.
VMRay said in a report shared with Cyber Security News (CSN) that the campaign combines mass malware delivery, a proxy botnet, targeted intrusion tooling, and AI-assisted influence operations.
The impact extends beyond data theft. Compromised devices can become relay points for attacker traffic, while stolen passwords, browser data, session cookies, and Active Directory credentials may support deeper access to corporate networks.
The use of multiple payloads also makes containment harder, as security teams may face several persistence methods and malicious processes at once.
Operation STANDOFF
Operation STANDOFF’s most notable infrastructure trick involves servers that answer unsolicited requests with an HTTP 301 redirect to GitHub.
This can make a suspicious host look like an ordinary redirector during a quick scan, helping its command-and-control infrastructure blend into traffic patterns associated with a trusted service. GitHub itself was not compromised or involved in the campaign.
The proxy-list server at 212.193.30.45 supplied proxies.txt to infected machines, then redirected generic requests to GitHub.
Analysts linked this behavior to a wider cluster of campaign infrastructure, while a separate host, 212.193.30.29, served the STANDOFF COORD operator console.
This distinction matters because the console host performed a normal HTTP-to-HTTPS redirect rather than the GitHub redirect technique.

The campaign’s layered design resembles other cases where threat actors abuse familiar online services, such as this report on GitHub command control abuse, but STANDOFF uses GitHub primarily as a misleading redirect destination.
Malware, Proxies, and Intrusions
The initial loader dropped dozens of executables into a user-writable staging folder and used hidden command activity to launch them.
It also attempted to weaken Microsoft Defender, checked for security tools and virtual machines, and created persistence through registry entries, scheduled tasks, services, and startup items.
Those actions give the malware more time to steal data and keep infected machines available to the operators.
One component collected browser credentials, wallet-related information, and screenshots, while others enabled botnet control or cryptocurrency mining.

The proxy function is especially concerning because it can turn victims into unwitting traffic relays, a risk also seen in proxy botnet abuse cases. RedLine’s presence adds further risk because the stealer is built to capture sensitive user data and can support follow-on attacks.
The STANDOFF COORD console indicates that the group may coordinate human operators against enterprise environments.
It tracked systems by internal, external, and DMZ network segments, stored credentials and Kerberos tickets, and included shared notes, tasks, and scoring features.
Organizations should block the listed indicators, investigate suspicious outbound requests, protect privileged accounts, and use the guidance in this Active Directory attack checklist to reduce credential-theft and lateral-movement risks.
Security teams should also watch for unsigned executables launched from user-writable folders, unexpected Defender configuration changes, suspicious scheduled tasks, and malformed WinHTTP user-agent values.
Reviewing non-browser connections to the listed addresses and isolating affected hosts quickly can limit the chance that a single infection becomes a wider network incident.
![The HTTP 301 redirect to github[.]com in the Shodan banner for 212.193.30[.]45 (port 443) (Source - VMRay)](https://blog.shomoysoft.com/storage/blog-images/the20http2030120redirect20to20github5b5dcom20in20the20shodan20banner20for20212193305b5d4520port2044320source20-20vmray-574e2800.webp)
Defenders should treat redirects to trusted domains as one signal among many, then validate the server, certificate, network ownership, requested resource, and process that initiated the connection before deciding whether the activity is benign.
Indocators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| File name | setupx86x64install.exe | Initial pay-per-install loader |
| MD5 | e77221d7a4b47b9107ba1b61a551ca89 | Initial loader hash |
| SHA-1 | 95c5ae3fec0d900e4634e11b3ad81971e78e2b31 | Initial loader hash |
| SHA-256 | 22ebb950592ccc987fd1dab9ddcd34c4fc519975dc1b82e4a793dc038d2d8e41 | Initial loader hash |
| Campaign C2 IPs | 212.193.30.29, 212.193.30.45, 217.198.13.211 | STANDOFF console, proxy redirector, and operator host |
| Campaign domains | russianhackers.online, api.russianhackers.online, bull-drops.online, bull-drops.ru, bulldrops.online, bulldrops.ru, xn--90aguaqgfu.xn--p1ai, ggstandoff.online, zadrot.gg, influencesite.ru, gginfluence.influencesite.ru, www.mobilearena.online, mobilearena.online, xn----9sbhgocsfmg4a1kfg.xn--p1ai, www.xn----9sbhgocsfmg4a1kfg.xn--p1ai | Campaign infrastructure and lure domains |
| GitHub-proxied C2 cluster | 5.129.196.85, 5.129.208.108, 5.129.209.17, 5.129.209.58, 5.129.210.32, 5.129.210.139, 5.129.214.85, 5.129.216.104, 5.129.217.228, 5.129.219.114, 5.129.225.220, 5.129.226.97, 5.129.213.59, 5.129.213.241, 5.129.227.196, 5.129.231.176, 5.129.231.240, 5.129.233.99, 5.129.236.52, 5.129.236.68, 5.129.237.19, 5.129.237.53, 5.129.238.90, 5.129.238.104, 5.129.238.105, 5.129.239.229, 5.129.242.37, 37.252.21.227, 45.139.78.67, 46.149.70.188, 89.223.71.207, 90.156.224.57, 92.51.22.34, 93.183.80.126, 147.45.183.198, 147.45.237.231, 185.247.185.85, 188.225.39.252, 188.225.72.157, 188.225.82.125, 194.87.56.156, 194.87.131.30, 195.133.73.225, 212.60.21.249 | Servers associated with GitHub redirect behavior |
| RedLine C2 | 185.215.113.44:23759 | RedLine Stealer endpoint |
| Socelars C2 | www.wgqpw.com | Socelars endpoint |
| XMRig pool | pool.supportxmr.com:3333 | Monero mining pool |
| XMRig wallet | 8BFyHJmwhhxXo29aFXZrTJTWDbkiQFEsBBnj1VnHBcy9ZQ2NKEUGdKvZbWGRNYamgAgJ75jsX1bzDi | Attacker-controlled mining wallet |
| Amadey infrastructure | wfsdragon.ru/api/setStats.php, 104.247.81.99, 212.192.241.62, 185.215.113.35 | Loader panels and related infrastructure |
| SmokeLoader infrastructure | rcacademy.at/upload, 188.40.141.211 | SmokeLoader delivery infrastructure |
| Dead-drop resolvers | t.me/borderxra, t.me/jredmankun, noc.social/menaomi, qoto.org/mniami, pastebin.com/raw/A7dSG1te | Follow-on address resolution |
| Other downloader C2 | server5.trumops.com, 3.229.117.57, www.listincode.com, listincode.com, cloudjah.com, 65.108.69.168:16278, 23.88.118.113:23817 | Additional downloader infrastructure |
| PPI hosting | coffee-music-laptop.s3.pl-waw.scw.cloud/publisherinstaller, 151.115.10.x, hammajawa7dou.s3.nl-ams.scw.cloud/advertiserInstallerpowerOff.exe, 51.158.212 | Pay-per-install hosting |
| Payload hosting | cdn.discordapp.com/attachments/915539163787460658/917347672489349130/m | Payload hosting location |
| Victim tracking | iplogger.org paths 2ANpP6, 143up7, 1FRbw7, 1FEbw7 | Victim-tracking references |
| Decoy domains | all-mobile-pa1ments.com.mx, buyfootball.com.sg, buy-fantasy-gxmes.com.sg, new-androidapps.me, topniemannpickshop.cc, blvckxx | Unresolved domains in payload configurations |
| Staging path | %LOCALAPPDATA%\7zSCB82E89C | Loader staging directory |
| Dropped files | MONXXXXXXXX.exe | Randomized payload naming pattern |
| Persistence files | C.exe, RaptorMiner.exe, Driver.url, %APPDATA%\APPDATA.exe | Fake process and persistence artifacts |
| Scheduled task | Schedule.Service.1 | Logon-triggered task naming pattern |
| Services | VBoxGuest, VBoxMouse, VBoxSF, VBoxService, VBoxVideo, VBoxWddm | VirtualBox-named malicious services |
| Local listeners | TCP/31461, TCP/49703 | Observed local ports |
| Mutexes | Global\48yorbq6rm87zot, Global\9g8w kEecfMwgjiZ5i-O1fR-8gT0 | Host-based malware artifacts |
| Network signature | Corrupted WinHTTP user-agent, transmitted as control byte 0x02 | Distinctive network detection signal |
| Operator fingerprints | standoff.token, standoff.workspace, auth-storage, 217.198.13.211:8002 | STANDOFF COORD and Telegram farm artifacts |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.