Skip to content
Malware

Operation STANDOFF Hides Command-and-Control Traffic Behind GitHub Redirects

Operation STANDOFF is a Russian-speaking cybercrime campaign that turns a single infection into a wider compromise. Its installer delivers information stealers, loaders, a cryptocurrency miner, and botnet components, while operators can later focus on selected victims for direct network intrusion. T...

· Jul 28, 2026 · 6 min read · 👁 1 views
Operation STANDOFF Hides Command-and-Control Traffic Behind GitHub Redirects

Operation STANDOFF is a Russian-speaking cybercrime campaign that turns a single infection into a wider compromise.

Its installer delivers information stealers, loaders, a cryptocurrency miner, and botnet components, while operators can later focus on selected victims for direct network intrusion.

The campaign also uses gaming-themed content and automated outreach to draw people toward its malware delivery ecosystem.

The operation relies on a pay-per-install model that bundles several malware families into one package.

The observed sample installed RedLine, Raccoon Stealer, Amadey, SmokeLoader, Socelars, Glupteba, and XMRig, allowing the attackers to steal credentials, mine cryptocurrency, and retain access to infected systems.

Researchers at VMRay identified the activity after linking behavior that initially appeared unrelated, including dropped files, unusual network requests, and shared server infrastructure. 

VMRay said in a report shared with Cyber Security News (CSN) that the campaign combines mass malware delivery, a proxy botnet, targeted intrusion tooling, and AI-assisted influence operations.

The impact extends beyond data theft. Compromised devices can become relay points for attacker traffic, while stolen passwords, browser data, session cookies, and Active Directory credentials may support deeper access to corporate networks.

The use of multiple payloads also makes containment harder, as security teams may face several persistence methods and malicious processes at once.

Operation STANDOFF

Operation STANDOFF’s most notable infrastructure trick involves servers that answer unsolicited requests with an HTTP 301 redirect to GitHub.

This can make a suspicious host look like an ordinary redirector during a quick scan, helping its command-and-control infrastructure blend into traffic patterns associated with a trusted service. GitHub itself was not compromised or involved in the campaign.

The proxy-list server at 212.193.30.45 supplied proxies.txt to infected machines, then redirected generic requests to GitHub.

Analysts linked this behavior to a wider cluster of campaign infrastructure, while a separate host, 212.193.30.29, served the STANDOFF COORD operator console.

This distinction matters because the console host performed a normal HTTP-to-HTTPS redirect rather than the GitHub redirect technique.

MITRE ATT&CK techniques observed (Source - VMRay)
MITRE ATT&CK techniques observed (Source – VMRay)

The campaign’s layered design resembles other cases where threat actors abuse familiar online services, such as this report on GitHub command control abuse, but STANDOFF uses GitHub primarily as a misleading redirect destination.

Malware, Proxies, and Intrusions

The initial loader dropped dozens of executables into a user-writable staging folder and used hidden command activity to launch them.

It also attempted to weaken Microsoft Defender, checked for security tools and virtual machines, and created persistence through registry entries, scheduled tasks, services, and startup items.

Those actions give the malware more time to steal data and keep infected machines available to the operators.

One component collected browser credentials, wallet-related information, and screenshots, while others enabled botnet control or cryptocurrency mining.

Process Tree (Source - VMRay)
Process Tree (Source – VMRay)

The proxy function is especially concerning because it can turn victims into unwitting traffic relays, a risk also seen in proxy botnet abuse cases. RedLine’s presence adds further risk because the stealer is built to capture sensitive user data and can support follow-on attacks.

The STANDOFF COORD console indicates that the group may coordinate human operators against enterprise environments.

It tracked systems by internal, external, and DMZ network segments, stored credentials and Kerberos tickets, and included shared notes, tasks, and scoring features.

Organizations should block the listed indicators, investigate suspicious outbound requests, protect privileged accounts, and use the guidance in this Active Directory attack checklist to reduce credential-theft and lateral-movement risks.

Security teams should also watch for unsigned executables launched from user-writable folders, unexpected Defender configuration changes, suspicious scheduled tasks, and malformed WinHTTP user-agent values.

Reviewing non-browser connections to the listed addresses and isolating affected hosts quickly can limit the chance that a single infection becomes a wider network incident.

The HTTP 301 redirect to github[.]com in the Shodan banner for 212.193.30[.]45 (port 443) (Source - VMRay)
The HTTP 301 redirect to github[.]com in the Shodan banner for 212.193.30[.]45 (port 443) (Source – VMRay)

Defenders should treat redirects to trusted domains as one signal among many, then validate the server, certificate, network ownership, requested resource, and process that initiated the connection before deciding whether the activity is benign.

Indocators of compromise (IoCs):-

TypeIndicatorDescription
File namesetupx86x64install.exeInitial pay-per-install loader
MD5e77221d7a4b47b9107ba1b61a551ca89Initial loader hash
SHA-195c5ae3fec0d900e4634e11b3ad81971e78e2b31Initial loader hash
SHA-25622ebb950592ccc987fd1dab9ddcd34c4fc519975dc1b82e4a793dc038d2d8e41Initial loader hash
Campaign C2 IPs212.193.30.29212.193.30.45217.198.13.211STANDOFF console, proxy redirector, and operator host
Campaign domainsrussianhackers.onlineapi.russianhackers.onlinebull-drops.onlinebull-drops.rubulldrops.onlinebulldrops.ruxn--90aguaqgfu.xn--p1aiggstandoff.onlinezadrot.gginfluencesite.rugginfluence.influencesite.ruwww.mobilearena.onlinemobilearena.onlinexn----9sbhgocsfmg4a1kfg.xn--p1aiwww.xn----9sbhgocsfmg4a1kfg.xn--p1aiCampaign infrastructure and lure domains
GitHub-proxied C2 cluster5.129.196.855.129.208.1085.129.209.175.129.209.585.129.210.325.129.210.1395.129.214.855.129.216.1045.129.217.2285.129.219.1145.129.225.2205.129.226.975.129.213.595.129.213.2415.129.227.1965.129.231.1765.129.231.2405.129.233.995.129.236.525.129.236.685.129.237.195.129.237.535.129.238.905.129.238.1045.129.238.1055.129.239.2295.129.242.3737.252.21.22745.139.78.6746.149.70.18889.223.71.20790.156.224.5792.51.22.3493.183.80.126147.45.183.198147.45.237.231185.247.185.85188.225.39.252188.225.72.157188.225.82.125194.87.56.156194.87.131.30195.133.73.225212.60.21.249Servers associated with GitHub redirect behavior
RedLine C2185.215.113.44:23759RedLine Stealer endpoint
Socelars C2www.wgqpw.comSocelars endpoint
XMRig poolpool.supportxmr.com:3333Monero mining pool
XMRig wallet8BFyHJmwhhxXo29aFXZrTJTWDbkiQFEsBBnj1VnHBcy9ZQ2NKEUGdKvZbWGRNYamgAgJ75jsX1bzDiAttacker-controlled mining wallet
Amadey infrastructurewfsdragon.ru/api/setStats.php104.247.81.99212.192.241.62185.215.113.35Loader panels and related infrastructure
SmokeLoader infrastructurercacademy.at/upload188.40.141.211SmokeLoader delivery infrastructure
Dead-drop resolverst.me/borderxrat.me/jredmankunnoc.social/menaomiqoto.org/mniamipastebin.com/raw/A7dSG1teFollow-on address resolution
Other downloader C2server5.trumops.com3.229.117.57www.listincode.comlistincode.comcloudjah.com65.108.69.168:1627823.88.118.113:23817Additional downloader infrastructure
PPI hostingcoffee-music-laptop.s3.pl-waw.scw.cloud/publisherinstaller151.115.10.xhammajawa7dou.s3.nl-ams.scw.cloud/advertiserInstallerpowerOff.exe51.158.212Pay-per-install hosting
Payload hostingcdn.discordapp.com/attachments/915539163787460658/917347672489349130/mPayload hosting location
Victim trackingiplogger.org paths 2ANpP6143up71FRbw71FEbw7Victim-tracking references
Decoy domainsall-mobile-pa1ments.com.mxbuyfootball.com.sgbuy-fantasy-gxmes.com.sgnew-androidapps.metopniemannpickshop.ccblvckxxUnresolved domains in payload configurations
Staging path%LOCALAPPDATA%\7zSCB82E89CLoader staging directory
Dropped filesMONXXXXXXXX.exeRandomized payload naming pattern
Persistence filesC.exeRaptorMiner.exeDriver.url%APPDATA%\APPDATA.exeFake process and persistence artifacts
Scheduled taskSchedule.Service.1Logon-triggered task naming pattern
ServicesVBoxGuestVBoxMouseVBoxSFVBoxServiceVBoxVideoVBoxWddmVirtualBox-named malicious services
Local listenersTCP/31461TCP/49703Observed local ports
MutexesGlobal\48yorbq6rm87zotGlobal\9g8w kEecfMwgjiZ5i-O1fR-8gT0Host-based malware artifacts
Network signatureCorrupted WinHTTP user-agent, transmitted as control byte 0x02Distinctive network detection signal
Operator fingerprintsstandoff.tokenstandoff.workspaceauth-storage217.198.13.211:8002STANDOFF COORD and Telegram farm artifacts

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you