đ Contexte
PubliĂ© le 20 juillet 2026 par VMRay Labs (source : vmray.com), ce rapport prĂ©sente l’analyse complĂšte d’une campagne cybercriminelle russophone jusqu’alors non attribuĂ©e, baptisĂ©e Operation STANDOFF. La dĂ©couverte initiale provient d’un signal comportemental issu de la plateforme UniqueSignal de VMRay, Ă partir d’un Ă©chantillon analysĂ© le 13 mai 2026.
đŻ Vecteur initial et chaĂźne d’infection
L’Ă©chantillon initial, setup_x86_x64_install.exe (MD5 : e77221d7a4b47b9107ba1b61a551ca89), est un installeur NSIS de 16,65 Mo fonctionnant comme un loader Pay-Per-Install (PPI). Il dĂ©pose entre 40 et 50 exĂ©cutables dans %LOCALAPPDATA%\Temp\7zSCB82E89C\ sous des noms alĂ©atoires MONXXXXXXXX.exe et installe simultanĂ©ment plusieurs familles de malwares :
- Raccoon Stealer v1.7.2 (vol d’informations)
- RedLine Stealer (vol de credentials, MissionID
@Tui, C2 :185.215.113.44:23759) - Amadey (loader/bot)
- SmokeLoader (loader/backdoor modulaire)
- Socelars (vol de tokens, C2 :
www.wgqpw.com) - Glupteba (botnet/backdoor avec rootkit)
- XMRig v6.2.2 (minage Monero, pool
pool.supportxmr.com:3333) - WebBrowserPassView (vol de credentials navigateur)
đĄïž Ăvasion et persistance
Le bundle investit massivement dans l’Ă©vasion : dĂ©sactivation de Microsoft Defender (real-time monitoring, MAPS, exclusion du rĂ©pertoire de staging), dĂ©tection de 11 produits de sĂ©curitĂ© (Kaspersky, ESET, Avast, etc.), checks anti-VM (VirtualBox, Wine, hyperviseur via NtQuerySystemInformation), checks anti-debugger (IsDebuggerPresent, NtQueryInformationProcess), manipulation de timestamps, appels systĂšme directs/indirects pour contourner le hooking.
La persistance est établie via : un faux processus systÚme C:\Windows\rss\csrss.exe, des tùches planifiées (Schedule.Service.1), une clé Run RaptorMiner.exe, des services aux noms VirtualBox (VBoxGuest, VBoxMouse, VBoxSF, VBoxService, VBoxVideo, VBoxWddm), et des listeners TCP sur les ports 31461 et 49703.
đ Infrastructure C2 et pivoting
Deux serveurs C2 centraux, hébergés chez TimeWeb Ltd. (AS9123) en Russie :
212.193.30.29: sert/server.txtet hĂ©berge la console opĂ©rateur STANDOFF COORD (domainerussianhackers.online, certificat Let’s Encrypt)212.193.30.45: sert/proxies.txt; redirige tout trafic HTTP non sollicitĂ© vershttps://github.com/pour masquer l’infrastructure
Par pivoting sur les caractéristiques TLS/JARM et le comportement de redirection GitHub, 44 serveurs supplémentaires ont été identifiés sur TimeWeb Ltd., formant un cluster C2 étendu. Un User-Agent WinHTTP malformé (octets CJK corrompus, transmis comme un seul octet de contrÎle 0x02) constitue une signature réseau distinctive.
Des dead-drop resolvers sur Telegram (t.me/borderxra, t.me/jredmankun), Mastodon (noc.social/@menaomi, qoto.org/@mniami) et Pastebin assurent la résilience du C2.
đ„ïž Console multi-opĂ©rateurs STANDOFF COORD
La console, une application React single-page servie sur 212.193.30.29, est une plateforme collaborative d’intrusion ciblant les environnements Active Directory :
- Vault de credentials typés :
password,hash(NTLM),kerberos_ticket,api_token,cookie,private_key - Inventaire des hÎtes compromis par segment réseau (
internal,external,dmz) - SystÚme de tùches priorisées (P0-P3), états (
not_started,in_progress,confirmed_exploit, etc.) - Scoreboard par opérateur avec points
- Base de connaissances interne avec playbooks en russe
- Backend PostgreSQL, API sur
api.russianhackers.online - Interface en russe, planification en heure de Moscou
đŁ Plateforme d’influence IA (217.198.13.211)
Un second serveur héberge deux outils opérateurs distincts :
-
Ferme de comptes Telegram : automatisation complĂšte de l’authentification, gestion de proxies (consommant le pool du botnet), “warming” de comptes, rejoindre des canaux en masse, scraping de participants, gĂ©nĂ©ration de commentaires via GPT sous des personas configurables (nom, Ăąge, style, objectif) â systĂšme de comportement inauthentique coordonnĂ© (CIB).
-
Plateforme d’automatisation multi-canal : workflows visuels intĂ©grant Gmail/IMAP, Google Sheets, Claude (Anthropic), Telegram, WhatsApp, HTTP gĂ©nĂ©rique â campagnes de masse AI-driven sur email, Telegram et WhatsApp.
Le portail public “ĐĐŸĐ±ĐžĐ»ŃĐœĐ°Ń ĐŃĐ”ĐœĐ°” (Mobile Arena) sur le port 3000 sert de leurre gaming (Standoff 2, PUBG Mobile) pour attirer une audience jeune russophone vers l’infrastructure malveillante.
đ Type d’article
Il s’agit d’une publication de recherche et d’une analyse technique approfondie produite par VMRay Labs, visant Ă documenter une campagne inĂ©dite, fournir des IOCs exploitables et dĂ©montrer la valeur de l’analyse comportementale Ă niveau d’exĂ©cution pour la reconstruction de campagnes complexes.
đ§ TTPs et IOCs dĂ©tectĂ©s
Acteurs de menace
- Operation STANDOFF (cybercriminal) â
TTP
- T1059.001 â Command and Scripting Interpreter: PowerShell (Execution)
- T1055 â Process Injection (Defense Evasion)
- T1055.012 â Process Injection: Process Hollowing (Defense Evasion)
- T1562.001 â Impair Defenses: Disable or Modify Tools (Defense Evasion)
- T1497 â Virtualization/Sandbox Evasion (Defense Evasion)
- T1027 â Obfuscated Files or Information (Defense Evasion)
- T1036 â Masquerading (Defense Evasion)
- T1547.001 â Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (Persistence)
- T1053.005 â Scheduled Task/Job: Scheduled Task (Persistence)
- T1543.003 â Create or Modify System Process: Windows Service (Persistence)
- T1003 â OS Credential Dumping (Credential Access)
- T1539 â Steal Web Session Cookie (Credential Access)
- T1552.001 â Unsecured Credentials: Credentials In Files (Credential Access)
- T1557 â Adversary-in-the-Middle (Credential Access)
- T1102 â Web Service (Command and Control)
- T1090 â Proxy (Command and Control)
- T1568 â Dynamic Resolution (Command and Control)
- T1071.001 â Application Layer Protocol: Web Protocols (Command and Control)
- T1041 â Exfiltration Over C2 Channel (Exfiltration)
- T1113 â Screen Capture (Collection)
- T1005 â Data from Local System (Collection)
- T1083 â File and Directory Discovery (Discovery)
- T1082 â System Information Discovery (Discovery)
- T1057 â Process Discovery (Discovery)
- T1496 â Resource Hijacking (Impact)
- T1110.003 â Brute Force: Password Spraying (Credential Access)
- T1550.002 â Use Alternate Authentication Material: Pass the Hash (Lateral Movement)
- T1550.003 â Use Alternate Authentication Material: Pass the Ticket (Lateral Movement)
IOC
- IPv4 :
212.193.30.29â AbuseIPDB · VT · ThreatFox - IPv4 :
212.193.30.45â AbuseIPDB · VT · ThreatFox - IPv4 :
217.198.13.211â AbuseIPDB · VT · ThreatFox - IPv4 :
185.215.113.44â AbuseIPDB · VT · ThreatFox - IPv4 :
104.247.81.99â AbuseIPDB · VT · ThreatFox - IPv4 :
212.192.241.62â AbuseIPDB · VT · ThreatFox - IPv4 :
185.215.113.35â AbuseIPDB · VT · ThreatFox - IPv4 :
188.40.141.211â AbuseIPDB · VT · ThreatFox - IPv4 :
91.219.236.207â AbuseIPDB · VT · ThreatFox - IPv4 :
91.219.237.227â AbuseIPDB · VT · ThreatFox - IPv4 :
185.225.19.18â AbuseIPDB · VT · ThreatFox - IPv4 :
3.229.117.57â AbuseIPDB · VT · ThreatFox - IPv4 :
172.237.145.27â AbuseIPDB · VT · ThreatFox - IPv4 :
65.108.69.168â AbuseIPDB · VT · ThreatFox - IPv4 :
23.88.118.113â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.196.85â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.208.108â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.209.17â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.209.58â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.210.32â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.210.139â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.214.85â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.216.104â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.217.228â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.219.114â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.225.220â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.226.97â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.213.59â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.213.241â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.227.196â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.231.176â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.231.240â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.233.99â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.236.52â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.236.68â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.237.19â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.237.53â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.238.90â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.238.104â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.238.105â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.239.229â AbuseIPDB · VT · ThreatFox - IPv4 :
5.129.242.37â AbuseIPDB · VT · ThreatFox - IPv4 :
37.252.21.227â AbuseIPDB · VT · ThreatFox - IPv4 :
45.139.78.67â AbuseIPDB · VT · ThreatFox - IPv4 :
46.149.70.18â AbuseIPDB · VT · ThreatFox - IPv4 :
89.223.71.207â AbuseIPDB · VT · ThreatFox - IPv4 :
90.156.224.57â AbuseIPDB · VT · ThreatFox - IPv4 :
92.51.22.34â AbuseIPDB · VT · ThreatFox - IPv4 :
93.183.80.126â AbuseIPDB · VT · ThreatFox - IPv4 :
147.45.183.198â AbuseIPDB · VT · ThreatFox - IPv4 :
147.45.237.23â AbuseIPDB · VT · ThreatFox - IPv4 :
185.247.185.85â AbuseIPDB · VT · ThreatFox - IPv4 :
188.225.39.252â AbuseIPDB · VT · ThreatFox - IPv4 :
188.225.72.157â AbuseIPDB · VT · ThreatFox - IPv4 :
188.225.82.125â AbuseIPDB · VT · ThreatFox - IPv4 :
194.87.56.156â AbuseIPDB · VT · ThreatFox - IPv4 :
194.87.131.30â AbuseIPDB · VT · ThreatFox - IPv4 :
195.133.73.225â AbuseIPDB · VT · ThreatFox - IPv4 :
212.60.21.249â AbuseIPDB · VT · ThreatFox - Domaines :
russianhackers.onlineâ VT · URLhaus · ThreatFox - Domaines :
api.russianhackers.onlineâ VT · URLhaus · ThreatFox - Domaines :
bull-drops.onlineâ VT · URLhaus · ThreatFox - Domaines :
bull-drops.ruâ VT · URLhaus · ThreatFox - Domaines :
bulldrops.onlineâ VT · URLhaus · ThreatFox - Domaines :
bulldrops.ruâ VT · URLhaus · ThreatFox - Domaines :
xn--90aguaqgfu.xn--p1aiâ VT · URLhaus · ThreatFox - Domaines :
ggstandoff.onlineâ VT · URLhaus · ThreatFox - Domaines :
zadrot.ggâ VT · URLhaus · ThreatFox - Domaines :
influencesite.ruâ VT · URLhaus · ThreatFox - Domaines :
gginfluence.influencesite.ruâ VT · URLhaus · ThreatFox - Domaines :
www.mobilearena.onlineâ VT · URLhaus · ThreatFox - Domaines :
mobilearena.onlineâ VT · URLhaus · ThreatFox - Domaines :
xn----9sbhgocsfmg4a1kfg.xn--p1aiâ VT · URLhaus · ThreatFox - Domaines :
www.xn----9sbhgocsfmg4a1kfg.xn--p1aiâ VT · URLhaus · ThreatFox - Domaines :
www.wgqpw.comâ VT · URLhaus · ThreatFox - Domaines :
wfsdragon.ruâ VT · URLhaus · ThreatFox - Domaines :
rcacademy.atâ VT · URLhaus · ThreatFox - Domaines :
server5.trumops.comâ VT · URLhaus · ThreatFox - Domaines :
www.listincode.comâ VT · URLhaus · ThreatFox - Domaines :
listincode.comâ VT · URLhaus · ThreatFox - Domaines :
cloudjah.comâ VT · URLhaus · ThreatFox - Domaines :
loopaai.ruâ VT · URLhaus · ThreatFox - Domaines :
all-mobile-pa1ments.com.mxâ VT · URLhaus · ThreatFox - Domaines :
buy-fantasy-football.com.sgâ VT · URLhaus · ThreatFox - Domaines :
buy-fantasy-gxmes.com.sgâ VT · URLhaus · ThreatFox - Domaines :
new-androidapps.meâ VT · URLhaus · ThreatFox - Domaines :
topniemannpickshop.ccâ VT · URLhaus · ThreatFox - Domaines :
blvckxxx.beget.techâ VT · URLhaus · ThreatFox - URLs :
http://212.193.30.29/server.txtâ URLhaus - URLs :
http://212.193.30.45/proxies.txtâ URLhaus - URLs :
http://t.me/borderxraâ URLhaus - URLs :
http://t.me/jredmankunâ URLhaus - URLs :
https://noc.social/@menaomiâ URLhaus - URLs :
https://qoto.org/@mniamiâ URLhaus - URLs :
https://pastebin.com/raw/A7dSG1teâ URLhaus - URLs :
http://iplogger.org/2ANpP6â URLhaus - URLs :
http://iplogger.org/143up7â URLhaus - URLs :
http://iplogger.org/1FRbw7â URLhaus - URLs :
http://iplogger.org/1FEbw7â URLhaus - URLs :
http://wfsdragon.ru/api/setStats.phpâ URLhaus - URLs :
http://212.192.241.62/base/api/statistics.phpâ URLhaus - URLs :
http://185.215.113.35/d2VxjasuwS/index.phpâ URLhaus - URLs :
http://rcacademy.at/upload/â URLhaus - URLs :
http://91.219.236.207/borderxraâ URLhaus - URLs :
http://91.219.237.227/borderxraâ URLhaus - URLs :
http://185.225.19.18/borderxraâ URLhaus - URLs :
http://cloudjah.com/77_1.exeâ URLhaus - URLs :
https://coffee-music-laptop.s3.pl-waw.scw.cloud/publisher_installer/powerOff.exeâ URLhaus - URLs :
https://hammajawa7dou.s3.nl-ams.scw.cloud/advertiser_Installer/powerOff.exeâ URLhaus - URLs :
https://cdn.discordapp.com/attachments/915539163787460658/917347672489349130/myfile.exeâ URLhaus - SHA256 :
22ebb950592ccc987fd1dab9ddcd34c4fc519975dc1b82e4a793dc038d2d8e41â VT · MalwareBazaar - SHA1 :
95c5ae3fec0d900e4634e11b3ad81971e78e2b31â VT · MalwareBazaar - MD5 :
e77221d7a4b47b9107ba1b61a551ca89â VT · MalwareBazaar - CVEs :
CVE-2021-34527â NVD · CIRCL - Fichiers :
setup_x86_x64_install.exe - Fichiers :
csrss.exe - Fichiers :
RaptorMiner.exe - Fichiers :
Driver.url - Fichiers :
injector.exe - Fichiers :
powerOff.exe - Chemins :
%LOCALAPPDATA%\Temp\7zSCB82E89C\ - Chemins :
C:\Windows\rss\csrss.exe - Chemins :
%APPDATA%\Roaming\teieedr - Chemins :
%APPDATA%\Roaming\Sysfiles\Driver.exe
Malware / Outils
- Raccoon Stealer (stealer)
- RedLine Stealer (stealer)
- Amadey (loader)
- SmokeLoader (loader)
- Socelars (stealer)
- Glupteba (botnet)
- XMRig (other)
- WebBrowserPassView (tool)
- STANDOFF COORD (framework)
- GG Influence (other)
đą Indice de vĂ©rification factuelle : 75/100 (haute)
- ⏠vmray.com â source non rĂ©fĂ©rencĂ©e (0pts)
- â 64754 chars â texte complet (fulltext extrait) (15pts)
- â 124 IOCs dont des hashes (15pts)
- â 6/10 IOCs confirmĂ©s (AbuseIPDB, MalwareBazaar, ThreatFox, URLhaus, VirusTotal) (15pts)
- â 28 TTPs MITRE identifiĂ©es (15pts)
- â date extraite du HTML source (10pts)
- â acteur(s) identifiĂ©(s) : Operation STANDOFF (5pts)
- ⏠0/1 CVE(s) confirmée(s) (0pts)
IOCs confirmés externellement :
212.193.30.29(ip) â VT (12/91 dĂ©tections)212.193.30.45(ip) â VT (17/91 dĂ©tections)22ebb950592ccc98âŠ(sha256) â VT (48/75 dĂ©tections)russianhackers.online(domain) â VT (4/91 dĂ©tections)api.russianhackers.online(domain) â VT (3/91 dĂ©tections)
đ Source originale : https://www.vmray.com/execution-level-analysis-of-a-russian-speaking-multi-operator-intrusion-campaign-operation-standoff/?utm_source=substack&utm_medium=email