OPERATION STANDOFF is a Russian-speaking cybercriminal operation utilizing pay-per-install malware, proxy-botnets, and hands-on-keyboard intrusion tactics targeting primarily Russian-speaking mobile gamers and corporate networks. VMRay Labs identified this operation through a specific malware detection that revealed a complex infrastructure involving at least 44 command and control (C2) servers, leveraging GitHub redirects to conceal its activities.
The malware, notably consisting of several known stealers and a Monero miner, disables security tools to establish persistent access. The campaign is linked to Russian operators, yet no arrests have been made and the full scale of its impact remains uncertain.