Operation STANDOFF: A Campaign Hiding C2 Behind GitHub Redirects
Essential information
- Published
- 21/07/2026 13:39
- Modified
- —
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- active-directory-targeting ai-driven-influence amadey github-redirect-concealment glupteba pay-per-install proxy-botnet raccoon stealer redline russian-speaking smokeloader socelars telegram-account-farm timeweb-infrastructure xmrig
- Related entities
- 1 vulnerabilities (cve), 72 indicators, 71 observables, 1 intrusion sets (apt), 28 techniques (mitre), 7 malware
Description
VMRay Labs uncovered a sophisticated Russian-speaking cybercriminal operation combining multiple attack vectors on shared infrastructure. The campaign distributes commodity stealers including Raccoon, RedLine, Amadey, SmokeLoader, Socelars, and Glupteba through a pay-per-install loader while enrolling victims into a proxy-botnet. Command-and-control servers on Russian provider TimeWeb use GitHub domain redirects for concealment. A custom multi-operator console called STANDOFF COORD coordinates hands-on-keyboard intrusions targeting Active Directory environments, storing NTLM hashes, Kerberos tickets, and credentials organized by network segments. Additionally, the infrastructure hosts an AI-driven influence operation using industrial-scale Telegram account farms and automated engagement platforms targeting Russian-speaking mobile gaming communities through a portal called Mobile Arena, driving traffic toward gambling sites and malware distribution.