VMRay Labs detailed Operation STANDOFF, a previously unattributed Russian-speaking cybercriminal campaign that delivers multiple payloads through a pay-per-install NSIS loader masquerading as setup_x86_x64_install.exe. The operation has been observed deploying Raccoon Stealer, RedLine Stealer, Amadey, SmokeLoader, Socelars, Glupteba, XMRig, and WebBrowserPassView, combining credential theft, botnet activity, and cryptomining in a single infection chain. Researchers said the operators used layered evasion and persistence techniques, including disabling Microsoft Defender, anti-VM and anti-debug checks, scheduled tasks, registry Run keys, fake VirtualBox-named services, and a masqueraded csrss.exe path, while a gaming-themed “Mobile Arena” lure targeted young Russian-speaking users.
The campaign’s infrastructure included command-and-control systems hosted on TimeWeb Ltd., a broader 44-server cluster, and dead-drop resolvers on Telegram, Mastodon, and Pastebin. Additional reporting tied the operation to command-and-control traffic concealed behind GitHub redirects and exposed indicators including suspicious installer filenames, hashes, domains, IP addresses, Telegram and social-media handles, anti-virtualization artifacts, and Monero mining infrastructure such as pool.supportxmr.com:3333. VMRay also identified STANDOFF COORD, a Russian-language multi-operator console designed for Active Directory intrusion, alongside a separate AI-enabled influence platform used for Telegram account farming and mass messaging.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
VMRay Labs first detected the previously unattributed Russian-speaking cybercriminal campaign later named Operation STANDOFF through behavioral telemetry. The initial detection was explicitly anchored to May 13, 2026.
VMRay Labs published a technical analysis describing Operation STANDOFF as a multi-layered campaign using an NSIS pay-per-install loader to deploy multiple malware families, along with AD-focused intrusion tooling and an AI-enabled influence platform. The report also detailed infrastructure on TimeWeb, dead-drop resolvers on Telegram, Mastodon, and Pastebin, and a gaming-themed "Mobile Arena" lure targeting Russian-speaking users.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcecyberveille.ch
Open sourcevmray.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.