RST TI Report Digest: 27 Jul 2026
ID: 2f7f651a-1195-5e49-bacd-77ff83816ae0
STIX ID: report--2f7f651a-1195-5e49-bacd-77ff83816ae0
Feed Name: RST Cloud Blog
Operation STANDOFF is a Russian-speaking multi-operator cybercriminal campaign that uses pay-per-install loaders to deploy infostealers (Raccoon Stealer, RedLine), disguises traffic to mimic legitimate services, and operates C2/proxy infrastructure (notably 212.193.30.29 and 212.193.30.45) to harvest credentials, manage compromised hosts, and support broader fraud and AI-assisted influence activities; the report contains execution-level analysis and extensive IOCs (IPs, domains, URLs, and sample hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
