Operation STANDOFF Hides Command-and-Control Traffic Behind GitHub Redirects

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Operation STANDOFF is a Russian-speaking cybercrime campaign that turns a single infection into a wider compromise.

Its installer delivers information stealers, loaders, a cryptocurrency miner, and botnet components, while operators can later focus on selected victims for direct network intrusion.

The campaign also uses gaming-themed content and automated outreach to draw people toward its malware delivery ecosystem.

The operation relies on a pay-per-install model that bundles several malware families into one package.

The observed sample installed RedLine, Raccoon Stealer, Amadey, SmokeLoader, Socelars, Glupteba, and XMRig, allowing the attackers to steal credentials, mine cryptocurrency, and retain access to infected systems.

Researchers at VMRay identified the activity after linking behavior that initially appeared unrelated, including dropped files, unusual network requests, and shared server infrastructure. 

VMRay said in a report shared with Cyber Security News (CSN) that the campaign combines mass malware delivery, a proxy botnet, targeted intrusion tooling, and AI-assisted influence operations.

The impact extends beyond data theft. Compromised devices can become relay points for attacker traffic, while stolen passwords, browser data, session cookies, and Active Directory credentials may support deeper access to corporate networks.

The use of multiple payloads also makes containment harder, as security teams may face several persistence methods and malicious processes at once.

Operation STANDOFF

Operation STANDOFF’s most notable infrastructure trick involves servers that answer unsolicited requests with an HTTP 301 redirect to GitHub.

This can make a suspicious host look like an ordinary redirector during a quick scan, helping its command-and-control infrastructure blend into traffic patterns associated with a trusted service. GitHub itself was not compromised or involved in the campaign.

The proxy-list server at 212.193.30.45 supplied proxies.txt to infected machines, then redirected generic requests to GitHub.

Analysts linked this behavior to a wider cluster of campaign infrastructure, while a separate host, 212.193.30.29, served the STANDOFF COORD operator console.

This distinction matters because the console host performed a normal HTTP-to-HTTPS redirect rather than the GitHub redirect technique.

MITRE ATT&CK techniques observed (Source – VMRay)

The campaign’s layered design resembles other cases where threat actors abuse familiar online services, such as this report on GitHub command control abuse, but STANDOFF uses GitHub primarily as a misleading redirect destination.

Malware, Proxies, and Intrusions

The initial loader dropped dozens of executables into a user-writable staging folder and used hidden command activity to launch them.

It also attempted to weaken Microsoft Defender, checked for security tools and virtual machines, and created persistence through registry entries, scheduled tasks, services, and startup items.

Those actions give the malware more time to steal data and keep infected machines available to the operators.

One component collected browser credentials, wallet-related information, and screenshots, while others enabled botnet control or cryptocurrency mining.

Process Tree (Source – VMRay)

The proxy function is especially concerning because it can turn victims into unwitting traffic relays, a risk also seen in proxy botnet abuse cases. RedLine’s presence adds further risk because the stealer is built to capture sensitive user data and can support follow-on attacks.

The STANDOFF COORD console indicates that the group may coordinate human operators against enterprise environments.

It tracked systems by internal, external, and DMZ network segments, stored credentials and Kerberos tickets, and included shared notes, tasks, and scoring features.

Organizations should block the listed indicators, investigate suspicious outbound requests, protect privileged accounts, and use the guidance in this Active Directory attack checklist to reduce credential-theft and lateral-movement risks.

Security teams should also watch for unsigned executables launched from user-writable folders, unexpected Defender configuration changes, suspicious scheduled tasks, and malformed WinHTTP user-agent values.

Reviewing non-browser connections to the listed addresses and isolating affected hosts quickly can limit the chance that a single infection becomes a wider network incident.

The HTTP 301 redirect to github[.]com in the Shodan banner for 212.193.30[.]45 (port 443) (Source – VMRay)

Defenders should treat redirects to trusted domains as one signal among many, then validate the server, certificate, network ownership, requested resource, and process that initiated the connection before deciding whether the activity is benign.

Indocators of compromise (IoCs):-

Type Indicator Description
File name setupx86x64install.exe Initial pay-per-install loader
MD5 e77221d7a4b47b9107ba1b61a551ca89 Initial loader hash
SHA-1 95c5ae3fec0d900e4634e11b3ad81971e78e2b31 Initial loader hash
SHA-256 22ebb950592ccc987fd1dab9ddcd34c4fc519975dc1b82e4a793dc038d2d8e41 Initial loader hash
Campaign C2 IPs 212.193.30.29212.193.30.45217.198.13.211 STANDOFF console, proxy redirector, and operator host
Campaign domains russianhackers.onlineapi.russianhackers.onlinebull-drops.onlinebull-drops.rubulldrops.onlinebulldrops.ruxn--90aguaqgfu.xn--p1aiggstandoff.onlinezadrot.gginfluencesite.rugginfluence.influencesite.ruwww.mobilearena.onlinemobilearena.onlinexn----9sbhgocsfmg4a1kfg.xn--p1aiwww.xn----9sbhgocsfmg4a1kfg.xn--p1ai Campaign infrastructure and lure domains
GitHub-proxied C2 cluster 5.129.196.855.129.208.1085.129.209.175.129.209.585.129.210.325.129.210.1395.129.214.855.129.216.1045.129.217.2285.129.219.1145.129.225.2205.129.226.975.129.213.595.129.213.2415.129.227.1965.129.231.1765.129.231.2405.129.233.995.129.236.525.129.236.685.129.237.195.129.237.535.129.238.905.129.238.1045.129.238.1055.129.239.2295.129.242.3737.252.21.22745.139.78.6746.149.70.18889.223.71.20790.156.224.5792.51.22.3493.183.80.126147.45.183.198147.45.237.231185.247.185.85188.225.39.252188.225.72.157188.225.82.125194.87.56.156194.87.131.30195.133.73.225212.60.21.249 Servers associated with GitHub redirect behavior
RedLine C2 185.215.113.44:23759 RedLine Stealer endpoint
Socelars C2 www.wgqpw.com Socelars endpoint
XMRig pool pool.supportxmr.com:3333 Monero mining pool
XMRig wallet 8BFyHJmwhhxXo29aFXZrTJTWDbkiQFEsBBnj1VnHBcy9ZQ2NKEUGdKvZbWGRNYamgAgJ75jsX1bzDi Attacker-controlled mining wallet
Amadey infrastructure wfsdragon.ru/api/setStats.php104.247.81.99212.192.241.62185.215.113.35 Loader panels and related infrastructure
SmokeLoader infrastructure rcacademy.at/upload188.40.141.211 SmokeLoader delivery infrastructure
Dead-drop resolvers t.me/borderxrat.me/jredmankunnoc.social/menaomiqoto.org/mniamipastebin.com/raw/A7dSG1te Follow-on address resolution
Other downloader C2 server5.trumops.com3.229.117.57www.listincode.comlistincode.comcloudjah.com65.108.69.168:1627823.88.118.113:23817 Additional downloader infrastructure
PPI hosting coffee-music-laptop.s3.pl-waw.scw.cloud/publisherinstaller151.115.10.xhammajawa7dou.s3.nl-ams.scw.cloud/advertiserInstallerpowerOff.exe51.158.212 Pay-per-install hosting
Payload hosting cdn.discordapp.com/attachments/915539163787460658/917347672489349130/m Payload hosting location
Victim tracking iplogger.org paths 2ANpP6143up71FRbw71FEbw7 Victim-tracking references
Decoy domains all-mobile-pa1ments.com.mxbuyfootball.com.sgbuy-fantasy-gxmes.com.sgnew-androidapps.metopniemannpickshop.ccblvckxx Unresolved domains in payload configurations
Staging path %LOCALAPPDATA%7zSCB82E89C Loader staging directory
Dropped files MONXXXXXXXX.exe Randomized payload naming pattern
Persistence files C.exeRaptorMiner.exeDriver.url%APPDATA%APPDATA.exe Fake process and persistence artifacts
Scheduled task Schedule.Service.1 Logon-triggered task naming pattern
Services VBoxGuestVBoxMouseVBoxSFVBoxServiceVBoxVideoVBoxWddm VirtualBox-named malicious services
Local listeners TCP/31461TCP/49703 Observed local ports
Mutexes Global48yorbq6rm87zotGlobal9g8w kEecfMwgjiZ5i-O1fR-8gT0 Host-based malware artifacts
Network signature Corrupted WinHTTP user-agent, transmitted as control byte 0x02 Distinctive network detection signal
Operator fingerprints standoff.tokenstandoff.workspaceauth-storage217.198.13.211:8002 STANDOFF COORD and Telegram farm artifacts

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.