Researchers have identified Operation STANDOFF, a Russian-speaking cybercrime campaign that employs a pay-per-install loader to disable Microsoft Defender, deploy multiple malware families, and establish long-term access through a fake csrss.exe process. The operation integrates credential theft, cryptocurrency mining, proxy-botnet activities, targeted corporate intrusion tools, and AI-assisted influence operations on shared infrastructure. These payloads offer several monetization options: stealing browser credentials and cryptocurrency wallet data, enrolling systems into a botnet, mining Monero, and retaining access for future activities.
It utilizes PowerShell commands to disable Microsoft Defender's real-time monitoring, halt automatic sample submissions, block MAPS cloud reporting, and add the malware staging directory to Defender exclusions.
Researchers noted anti-analysis checks for virtual machines, Wine, Sandboxie, debuggers, and security-tool DLLs, as well as timestamp tampering, file deletion, runtime unpacking, and direct or indirect system calls designed to evade detection. During sample execution, MITRE ATT&CK techniques were observed through the VMRay Platform (Source: vmray). This platform mapped out the following functionalities of STANDOFF COORD: - Target inventories - Agent check-ins - Credential storage - Evidence uploads - Task management - Shared playbooks - Tracking for passwords, NTLM hashes, Kerberos tickets, API tokens, cookies, and private keys STANDOFF COORD is designed to facilitate multi-operator intrusions into enterprise environments.












