216.73.216.197

Operation STANDOFF: A Campaign Hiding C2 Behind GitHub Redirects

· Published 21/07/2026 13:39

Export JSON

Essential information

Published
21/07/2026 13:39
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
active-directory-targeting ai-driven-influence amadey github-redirect-concealment glupteba pay-per-install proxy-botnet raccoon stealer redline russian-speaking smokeloader socelars telegram-account-farm timeweb-infrastructure xmrig
Related entities
1 vulnerabilities (cve), 72 indicators, 71 observables, 1 intrusion sets (apt), 28 techniques (mitre), 7 malware

Description

VMRay Labs uncovered a sophisticated cybercriminal operation combining multiple attack vectors on shared infrastructure. The campaign distributes commodity stealers including Raccoon, , , , Socelars, and Glupteba through a loader while enrolling victims into a proxy-botnet. Command-and-control servers on Russian provider TimeWeb use GitHub domain redirects for concealment. A custom multi-operator console called STANDOFF COORD coordinates hands-on-keyboard intrusions targeting Active Directory environments, storing NTLM hashes, Kerberos tickets, and credentials organized by network segments. Additionally, the infrastructure hosts an AI-driven influence operation using industrial-scale Telegram account farms and automated engagement platforms targeting mobile gaming communities through a portal called Mobile Arena, driving traffic toward gambling sites and malware distribution.

External references