Operation STANDOFF: Multi-Operator Intrusion Analysis
Unveiling Operation STANDOFF
A singular malicious installer served as the entry point into a vast criminal ecosystem that concurrently compromised endpoints, exfiltrated sensitive data, hijacked victim bandwidth as proxy relays, and orchestrated vast networks of artificial accounts. Security specialists at VMRay Labs designated this sophisticated campaign as Operation STANDOFF.
The initial compromise vector relied on a rogue Windows installer that executed a cascade of diverse malware payloads. The dropped toolkit comprised the Raccoon Stealer, RedLine, and Socelars infostealers; the Amadey and SmokeLoader droppers; the Glupteba botnet agent; and the XMRig cryptocurrency miner. Within a single execution cycle, the installer generated dozens of malicious artifacts and spawned up to 152 distinct processes.
Extensive Exfiltration and Evasion Capabilities
The deployed malware systematically harvested credentials, browser data, cryptocurrency wallet files, and desktop screenshots. Simultaneously, the payloads neutralized Microsoft Defender safeguards, terminated the Windows Update service, added malicious working paths to antivirus exclusion lists, and actively fingerprinted the host environment for security products. To achieve persistent access, the malware instantiated scheduled tasks, Windows services, and a spoofed csrss.exe process.
Furthermore, compromised hosts provided operational utility beyond mere data theft. The malware enrolled infected systems into proxy relay networks, allowing threat actors to route foreign internet traffic through victim IP addresses. This technique effectively obscured operator locations while launching subsequent attacks under the guise of legitimate consumer infrastructure.
Infrastructure Masquerading and Command Coordination
A portion of the command-and-control (C2) infrastructure disguised itself by redirecting unauthorized requests to GitHub’s official domain, deceiving automated scanning tools into classifying the nodes as benign. GitHub itself was not compromised; it served merely as a trusted redirection target.
Researchers identified at least 44 interconnected servers hosted by TimeWeb. One central node hosted the “STANDOFF COORD” management portal, which operators utilized to coordinate corporate network intrusions. The panel stored captured passwords, NTLM hashes, Kerberos tickets, session cookies, private keys, and API tokens.
Collaborative Operator Features
- Target Distribution: Allocated high-value network targets among participating campaign operators.
- Internal Mapping: Displayed compromised hosts across internal subnets and demilitarized zones (DMZs).
- Forensic Repository: Retained screen captures, memory dumps, and intercepted network traffic.
- Gamified Tasking: Permitted operators to assign tasks, maintain internal knowledge bases, communicate, and earn points for verified breaches.
Automated Telegram Farms and AI Engagement
Another server hosted an automated Telegram account farm. The management interface automatically onboarded accounts, retrieved authentication codes, assigned dedicated proxy servers, and gradually warmed up account activity to evade automated ban algorithms. Subsequently, bots joined channels, scraped target usernames, published comments, and engaged in direct messaging.
To emulate human interaction, the campaign integrated large language models (LLMs). Operators specified persona attributes including name, age, writing style, and narrative goals enabling the system to conduct natural conversations with real users. A separate platform automated mass distribution across email, Telegram, and WhatsApp, leveraging Anthropic’s Claude to draft persuasive messaging.
Front Portals and Campaign Attribution
The public-facing element of the operation centered around “Mobile Arena,” a portal dedicated to popular mobile titles such as *Standoff 2* and *PUBG Mobile*. The site attracted users with promises of free in-game items, virtual currency, promo codes, and loot box platforms. VMRay Labs assesses that visitors were subsequently funneled toward fraudulent services, gambling platforms, and malicious downloads.
Attribution across these disparate operations is substantiated by shared C2 servers, identical software modules, unified management panels, overlapping schedule timestamps, and references to “GG Influence” and “ggstandoff.” VMRay Labs concludes that a unified threat group combined mass infection pipelines, targeted enterprise intrusions, and automated social engagement. At the time of publication, significant portions of the infrastructure remained active, with several domains evading security vendor blocklists.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.