Stantinko is a long-running cybercriminal botnet and malware ecosystem active since at least 2012, best known for large-scale ad fraud, click fraud, browser-extension abuse, and later cryptomining. The operation has been associated with roughly half a million compromised systems and has been especially prevalent in Russia and Ukraine, with additional activity affecting Belarus and Kazakhstan. Stantinko is not a nation-state actor; it is a financially motivated criminal operation. The malware ecosystem is modular and has included Windows services, browser-extension installers, in-memory plugin loaders, Linux proxy malware, remote administration tooling, brute-force modules targeting content-management systems, social-network abuse components, and coin-mining payloads. Initial access has been linked to trojanized software installers and pirated-software lures distributed through download and torrent-style sites. On infected Windows hosts, Stantinko established persistence through multiple interdependent services capable of reinstalling one another, used custom obfuscation and encrypted communications, and executed plugins in memory to reduce forensic visibility. A defining feature of Stantinko was monetization through malicious browser extensions, notably The Safe Surfing and Teddy Protection, which masqueraded as protective or filtering tools while injecting advertisements, replacing search-engine links, intercepting clicks, and redirecting users to affiliate and advertising pages. These extensions targeted major browsers and were supported by dedicated downloader components. Stantinko also abused compromised websites and public code-hosting repositories as operational infrastructure. Observed plugins and subcomponents have included Adstantinko, FileTour-related delivery components, a plugin downloader service, a browser extension downloader service, a custom remote administration backdoor, a Google search automation module, a Facebook abuse bot, Joomla and WordPress brute-force tooling, a Linux Trojan proxy, and later CoinMiner.Stantinko. The Linux component functioned as a proxy on compromised servers and has been linked to brute-force compromise of internet-facing systems. The cryptomining branch deployed a heavily modified Monero miner that retrieved runtime configuration indirectly, loaded hashing logic in memory, suppressed competing miners, and paused activity under conditions likely to expose it. Stantinko is notable for strong defense evasion tradecraft, including source-level and binary obfuscation, control-flow flattening, string reconstruction at runtime, use of legitimate open-source code as cover, self-deleting or fileless execution patterns, and anti-analysis checks. Overall, Stantinko evolved from an ad-fraud botnet into a broader criminal platform capable of persistent access, payload delivery, proxying, brute forcing, social-platform abuse, and resource hijacking.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
560 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operating a campaign involving a Linux proxy trojan masquerading as httpd on compromised Linux servers; historically known for Windows-focused campaigns involving coin-miners and adware botnets.
Operators of the Stantinko botnet developed a new cryptomining module and used advanced anti-analysis and anti-detection obfuscation, including runtime string construction, source-level control-flow flattening, dead code, do-nothing code, and merged/nested flattened functions.
Botnet operators distributing a heavily obfuscated cryptomining module to mine Monero on compromised machines; previously associated with click fraud, ad injection, social network fraud, password stealing, and dictionary-based attacks against Joomla and WordPress sites to harvest server credentials.
The content is a GitHub repository page for ESET's malware IOC collection, specifically a directory named 'stantinko', indicating the page is about indicators of compromise associated with Stantinko.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.