logo

VMRay Exposes Operation STANDOFF, a Russian-Speaking Intrusion Campaign Hidden Behind GitHub

ID: 33f32543-8eb4-5a2c-944f-7c867e61b5fa

STIX ID: report--33f32543-8eb4-5a2c-944f-7c867e61b5fa

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-07-27

Date Updated: 2026-07-28

Author: Do Son

...
...

Operation STANDOFF is a Russian-speaking criminal operation that links a pay-per-install loader distributing multiple info-stealers and a miner with a proxy-botnet, a multi-tenant intrusion console and an AI-driven influence platform targeting Russian-speaking mobile gamers and corporate Active Directory networks; analysts observed 44 related servers, GitHub redirector abuse, extensive persistence and anti-security actions, and recommend immediate blocking of indicators, hunting for malformed User-Agent requests, and auditing/rotating credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.