Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors operation standoff

operation standoff

TLP:CLEAR
Active

Also known as: tracked as, Silent, BirdTroy, DriveTroy, DevMan

Description

Operation Standoff first surfaced in VMRay analyses of anomalous Russian‑speaking intrusions. The group employs a multi‑operator infrastructure that includes commodity stealers such as Raccoon, RedLine, and Amadey; custom loaders like MATCHBOIL, LUNCHPOKE, and BURNYBEAR; and a proxy botnet for traffic obfuscation. Command‑and‑control channels are frequently routed through GitHub redirects or dynamic DNS callbacks to evade detection. Initial access vectors range from zero‑click phishing (“beehive”) to exploitation of high‑profile CVEs (CVE‑2021‑4034, CVE‑2021‑3156, CVE‑2017‑7269) and supply‑chain compromises. After compromising a host, the adversaries perform hands‑on credential harvesting in Active Directory environments. Tools such as Telemiris (Tomiris) facilitate NTLM hash collection, Kerberos ticket theft, and lateral movement via Pass‑the‑Ticket/Pass‑the‑Hash. They also deploy process hollowing of benign binaries like notepad.exe, use PowerShell for execution, and modify Windows registry or service objects to maintain persistence. The group supplements these tactics with crypto‑mining (XMRig) and ransomware variants such as Qilin to monetize compromised assets. An AI‑driven influence component operates in parallel. The actor farms fake Telegram accounts and uses GPT‑generated personas to promote gambling content and distribute malware within Russian‑speaking mobile gaming communities. Staging infrastructure on Alibaba Cloud, Microsoft 365 calendars, and other legitimate cloud services supports simultaneous intrusions across multiple regions, underpinning the group’s wide geographical reach.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Healthcare
Education
Gaming
Critical infrastructure

Targeted Countries / Regions

KP
GB
US
CN
VN
KR
UA
CA
BR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 19 hours ago

Executive Summary

Operation Standoff is a Russian‑speaking threat actor whose sophisticated campaigns combine zero‑click phishing, known CVE exploitation, commodity stealers, and AI‑driven social influence to infiltrate financial‑service, government, defense, healthcare, education, gaming, and critical‑infrastructure sectors across 14 countries. Once inside, they harvest credentials via Pass‑the‑Ticket/hash techniques, deploy ransomware (Qilin) or crypto‑mining (XMRig), and conduct large‑scale lateral movement using a proxy botnet that hides C2 traffic behind GitHub redirects and dynamic DNS.

Goals & Targeting

Operation Standoff’s primary strategic objective is financial gain through a blend of data exfiltration, ransomware payouts, and cryptocurrency mining. By targeting sectors with high-value personal or corporate data—including finance, defense, healthcare, education, gaming, critical infrastructure, and OT environments—the actor maximizes the potential for monetization while also fostering influence campaigns that amplify its reach and complicate attribution.

Enhanced Description

Key Capabilities

  • Zero‑click phishing exploitation using the ‘beehive’ technique
  • Exploitation of known CVEs (CVE-2021-4034, CVE-2021-3156, CVE-2017-7269) for initial access and privilege escalation
  • Deployment of commodity stealers such as Raccoon, RedLine, Amadey, SmokeLoader, Socelars, Glupteba via a proxy botnet
  • Credential harvesting through fake portals and web‑based phishing sites
  • AI‑driven social influence campaigns with fake Telegram accounts targeting mobile gaming communities
  • Staging operations on cloud platforms (Alibaba Cloud, Microsoft 365) to launch concurrent intrusions
  • Embedding malicious backdoors in legitimate coding challenge projects and benign software
  • AppleScript‑based macOS backdoor that manipulates the TCC database for privilege escalation
  • Process hollowing of notepad.exe to enable persistence on Windows systems
  • Use of GitHub redirection links and dynamic DNS callbacks as command‑and‑control channels
  • Cryptocurrency mining (XMRig) on compromised hosts
  • Ransomware deployment (Qilin variant) for monetisation
  • Lateral movement via Pass‑the‑Ticket, Pass‑the‑Hash, credential dumping
  • Use of PowerShell scripts and process injection/hollowing for execution and defense evasion

MITRE ATT&CK Tactics

Initial Access
Execution
Privilege Escalation
Persistence
Defense Evasion
Discovery
Command and Control
Exfiltration
Credential Access

ATT&CK Techniques

T1003
T1005
T1018
T1036
T1041
T1053.005
T1053
T1055
T1055.012
T1059
T1059.001
T1071.001
T1071
T1082
T1083
T1090
T1102
T1110.003
T1110
T1113
T1496
T1497
T1543.003
T1543
T1547.001
T1547
T1550.002
T1550.003
T1550
T1551
T1552.001
T1552
T1553
T1557
T1568
T1574

Software / Tooling

Raccoon
RedLine
Amadey
SmokeLoader
Socelars
Glupteba
MATCHBOIL
LUNCHPOKE
BURNYBEAR
Pay‑Per‑Install loader
Tomiris
Telemiris
Qilin ransomware
XMRig miner
PatchAgent loader chain
HelloBackdoor
AppleScript backdoor
PowerShell backdoor

Campaigns & Victims

Operation Standoff exhibits a high operational tempo, frequently rotating callbacks, signing host binaries, and leveraging legitimate cloud services for both C2 and persistence. The group’s campaigns are geographically dispersed—spanning KP, GB, US, CN, VN, KR, UA, CA, BR—and target diverse sectors from finance to critical infrastructure. Notable past operations include the deployment of XMRig mining fleets within corporate networks, ransomware attacks using Qilin that leveraged stolen credentials for widespread lateral movement, and AI‑driven social influence campaigns disseminated through Telegram. The actor’s use of commodity malware alongside custom backdoors allows rapid adaptation to defensive postures. The combination of stealthy delivery methods, robust obfuscation layers, dynamic C2 pathways, and a mix of financial motives and influence objectives renders Operation Standoff highly adaptable to evolving cybersecurity defenses.

IOC Patterns

  • GitHub redirect URLs hosting malicious payloads
  • Fake Telegram account identifiers and AI‑generated persona profiles
  • Domains associated with credential‑harvesting portals impersonating governmental tax systems
  • Staging server domains on Alibaba Cloud used for intrusions across multiple regions
  • CVE-based vulnerability exploitation references (e.g., CVE-2021-4034, CVE-2021-3156)
  • AppleScript usage on macOS to modify TCC database
  • Command‑and‑Control beaconing via dynamic DNS and proxy networks

Recommended Actions

  • Apply security patches for known CVEs such as CVE-2021-4034, CVE-2021-3156, and CVE-2017-7269 immediately.
  • Monitor for suspicious GitHub redirects and domain activity associated with staging servers on cloud platforms.
  • Enforce robust email authentication (DMARC, SPF, DKIM) to mitigate zero‑click phishing attempts.
  • Deploy or upgrade EDR solutions that detect commodity malware, process hollowing, and PowerShell abuse.
  • Integrate threat intelligence feeds to identify and block fake Telegram accounts generated by the actor.
  • Segment network per zero‑trust principles and isolate cloud infrastructure from on‑prem systems.
  • Restrict usage of AppleScript on macOS endpoints or monitor for TCC database modifications.
  • Protect OT and PLC/HMI networks via strict access controls and file integrity monitoring.
  • Implement multi‑factor authentication and least privilege to limit lateral movement from compromised credentials.

Suggested Tags

Russian-speaking
Operation Standoff
Zero-click exploit
Credential harvesting
Fake Telegram accounts
AI influence campaign
Proxy botnet
Commodity malware
CVE-2021-4034
CVE-2021-3156
CVE-2017-7269
OT target
macOS backdoor
Windows PowerShell exploitation
MuddyWater association

Confidence Assessment

The available intelligence derives from multiple independent analyses, primarily VMRay forensic reports and open‑source IOC sharing. While the attribution to a Russian‑speaking adversarial entity is consistent across sources, the actor’s exact organizational affiliation remains uncertain, and there is limited publicly documented evidence of continuous operations beyond the 2023–2024 time frame. Consequently, confidence in the technical TTP profile is high, but strategic context such as long‑term goals or full attribution depth should be regarded with moderate certainty.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. https://securityonline.info/operation-standoff-russian-threat-group/ — Cited by AI analysis.
  2. https://www.linkedin.com/company/vmray — Cited by AI analysis.
  3. https://www.vmray.com/hydra-saiga-covert-espionage-and-infiltration-of-critical-utilities/ — Cited by AI analysis.
  4. https://risky.biz/risky-bulletin-linux-kernel-discloses-442-cves-as-ai-bugpocalypse-settles-in/ — Cited by AI analysis.
  5. https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-july-e89 — Cited by AI analysis.
  6. https://x.com/vmray?lang=en — Cited by AI analysis.
  7. https://cyberwatch.olezkaglobal.com/ — Cited by AI analysis.
  8. https://thisweekin4n6.com/2026/07/26/week-30-2026/ — Cited by AI analysis.
  9. https://www.vmray.com/threat-intelligence-insights-pivoting-off-the-blockchain/ — Cited by AI analysis.
  10. https://www.vmray.com/execution-level-analysis-of-a-russian-speaking-multi-operator-intrusion-campaign-operation-standoff/ — Cited by AI analysis.
  11. https://www.linkedin.com/pulse/tenexsignal-07212026-tenex-ai-anume — Cited by AI analysis.
  12. https://gamefaqs.gamespot.com/psp/932560-ace-combat-x-skies-of-deception/faqs/50682 — Cited by AI analysis.
  13. https://civilbeat.org/2025/10/officer-shot-in-honolulu-drug-operation-standoff-is-ongoing/ — Cited by AI analysis.
  14. https://www.instagram.com/bloodtribecommunications/?hl=en — Cited by AI analysis.
  15. https://jhmovie.fandom.com/wiki/List_of_Ghost_in_the_Shell:_SAC_2045_episodes — Cited by AI analysis.
  16. https://ministang.com/security.php — Cited by AI analysis.
  17. https://securityonline.info/ — Cited by AI analysis.
  18. https://www.securityonline.info/author/ddos/ — Cited by AI analysis.
  19. https://www.vmray.com/socialphish-open-source-phishing-toolkit-analysis/ — Cited by AI analysis.
  20. https://www.protekcyber.co.uk/threat-intelligence/ — Cited by AI analysis.
  21. https://rosti.bin.re/reports — Cited by AI analysis.
  22. https://mallory.ai/actors/019f9f78-407e-7116-80e9-ba7114b352f3 — Cited by AI analysis.
  23. https://news.risky.biz/risky-bulletin-linux-kernel-discloses-442-cves-as-ai-bugpocalypse-settles-in/ — Cited by AI analysis.
  24. https://floridapolitics.com/archives/807631-last-call-for-7-14-26-a-prime-time-read-of-whats-going-down-in-florida/ — Cited by AI analysis.
  25. https://cert.gov.ua/article/6318634 — Cited by AI analysis.
  26. https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent — Cited by AI analysis.
  27. https://securelist.com/tr/hellonet-vipnet/120700/ — Cited by AI analysis.
  28. https://www.group-ib.com/blog/jadeprox-china-nexus-triback-loader/ — Cited by AI analysis.
  29. https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography/ — Cited by AI analysis.
  30. https://opensourcemalware.com/blog/chainveil-and-vitevenom-dprk-polinrider-campaign/ — Cited by AI analysis.
  31. https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant/ — Cited by AI analysis.
  32. https://oj-sec.com/blog/20260721/ — Cited by AI analysis.
  33. https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/ — Cited by AI analysis.
  34. https://hunt.io/blog/open-directory-nginx-rift-ghost-cms-multi-cve/ — Cited by AI analysis.
  35. https://github.com/AlloySecureGroup/BlinkLinkSentiennel — Cited by AI analysis.
  36. https://github.com/optimuslabs-io/grokpatrol — Cited by AI analysis.
  37. https://tachyon.so/blog/what-happened-after-we-pushed-env-to-public-repo — Cited by AI analysis.
  38. https://spawn-queue.acm.org/doi/10.1145/3819083 — Cited by AI analysis.
  39. https://www.nist.gov/news-events/news/2026/07/security-guidelines-storage-infrastructure-draft-sp-800-209r1-available — Cited by AI analysis.
  40. https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days/ — Cited by AI analysis.
  41. https://wojciechregula.blog/post/golden-gate-appdata-protection/ — Cited by AI analysis.
  42. https://github.com/NetSPI/AD-PathFinder — Cited by AI analysis.
  43. https://github.com/secdev02/Incantation — Cited by AI analysis.
  44. https://www.usenix.org/conference/osdi26/presentation/sharma — Cited by AI analysis.
  45. https://github.com/xxyyue/llm-observer-proxy-go — Cited by AI analysis.
  46. https://github.com/inclusionAI/SingGuard-NSFA — Cited by AI analysis.
  47. https://openai.com/index/hugging-face-model-evaluation-security-incident/ — Cited by AI analysis.
  48. https://blogs.cisco.com/ai/introducing-antares-the-most-efficient-open-weight-ai-models-for-vulnerability-localization/ — Cited by AI analysis.
  49. https://www.pillar.security/blog/the-week-of-sandbox-escapes/ — Cited by AI analysis.
  50. https://arxiv.org/abs/2607.05993 — Cited by AI analysis.
  51. https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes/ — Cited by AI analysis.
  52. https://g3tsyst3m.com/initial%20access/Using-WebDav-to-Outsmart-Smartscreen,-MOTW,-and-that-Other-Alert/ — Cited by AI analysis.
  53. https://github.com/An0nUD4Y/Offensive-COM — Cited by AI analysis.
  54. https://mysk.blog/2026/07/23/macos-overwrite-app-executables/ — Cited by AI analysis.
  55. https://github.com/MatheuZSecurity/Furtex — Cited by AI analysis.
  56. https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/ — Cited by AI analysis.
  57. https://github.com/Icex0/wp2shell-poc — Cited by AI analysis.
  58. https://github.com/samyeyo/clx — Cited by AI analysis.
  59. https://7h3kn0w3r.github.io/blog/windows-data-deduplication/ — Cited by AI analysis.
  60. https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/ — Cited by AI analysis.
  61. https://arxiv.org/abs/2607.20216 — Cited by AI analysis.
  62. https://arxiv.org/abs/2512.17667 — Cited by AI analysis.
  63. https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions — Cited by AI analysis.
  64. https://www.ncsc.gov.uk/section/about-this-website/privacy-statement — Cited by AI analysis.
  65. https://cisa.gov — Cited by AI analysis.
  66. https://any.run — Cited by AI analysis.
  67. https://hunt.io — Cited by AI analysis.
  68. https://github.com — Cited by AI analysis.

Intel Summary

39

Techniques

70

Tools

0

Campaigns

18

IOCs

0

Observed Data

12

Tactics

Tags

APT Group
Cybercrime
Influence Operations
Botnet
Russian Speaking Threat Actor
Cyber Espionage
Russian-speaking
Multi‑operator
GitHub redirect C2
Critical infrastructure target
Proxy botnet
AI influence
Pay‑per‑install loader
Commodity malware
Credential theft
Supply chain compromise
Cryptocurrency mining
Ransomware
Pass the Ticket
Pass the Hash
DLL side-loading
Zero-day exploitation
Operation Standoff
Zero-click exploit
Credential harvesting
Fake Telegram accounts
AI influence campaign
CVE-2021-4034
CVE-2021-3156
CVE-2017-7269
OT target
macOS backdoor
Windows PowerShell exploitation
MuddyWater association

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
North Korea (KP)
Confidence
55%
Added
Jul 22, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.