VMRay Exposes Operation STANDOFF, a Russian-Speaking Intrusion Campaign Hidden Behind GitHub
ID: 33f32543-8eb4-5a2c-944f-7c867e61b5fa
STIX ID: report--33f32543-8eb4-5a2c-944f-7c867e61b5fa
Feed Name: securityonline.info
Operation STANDOFF is a Russian-speaking criminal operation that links a pay-per-install loader distributing multiple info-stealers and a miner with a proxy-botnet, a multi-tenant intrusion console and an AI-driven influence platform targeting Russian-speaking mobile gamers and corporate Active Directory networks; analysts observed 44 related servers, GitHub redirector abuse, extensive persistence and anti-security actions, and recommend immediate blocking of indicators, hunting for malformed User-Agent requests, and auditing/rotating credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
