Operation STANDOFF Disables Windows Defender and Installs Persistent Fake csrss.exe

Researchers have uncovered Operation STANDOFF, a Russian-speaking cybercrime campaign that uses a pay-per-install loader to disable Microsoft Defender, deploy several malware families, and establish long-term access through a fake csrss.exe process.

The operation combines credential theft, cryptocurrency mining, proxy-botnet activity, targeted corporate intrusion tooling, and AI-assisted influence operations on shared infrastructure.

The infection begins with setupx86x64install.exe, a 32-bit NSIS installer identified as a multi-payload loader rather than a single malware sample.

VMRay Labs observed the sample creating roughly 40 to 50 executable files in a randomized directory under %LOCALAPPDATA%, then using repeated hidden cmd.exe processes to launch them

The loader delivers a broad set of commodity malware, including RedLine Stealer, Raccoon Stealer, Amadey, SmokeLoader, Socelars, Glupteba, XMRig, and credential-recovery utilities.

These payloads give the operators several monetization options at once: stealing browser credentials and cryptocurrency-wallet data, enrolling systems into a botnet, mining Monero, and retaining access for later activity.

Operation STANDOFF Deploys Fake CSRSS

The campaign actively weakens endpoint defenses.

It uses PowerShell commands to turn off Microsoft Defender real-time monitoring, turn off automatic sample submission, block MAPS cloud reporting, and add the malware staging directory to Defender exclusions.

It also checks for security products from vendors including Avast, AVG, Bitdefender, ESET, Kaspersky, Norton, Panda, Sophos, and others.

VMRay Platform VTIs and extracted malware configurations (Source: vmray)
VMRay Platform VTIs and extracted malware configurations (Source: vmray)

In addition, the malware attempts to stop or delete the Windows Update service, potentially limiting security remediation.

Researchers also recorded anti-analysis checks for virtual machines, Wine, Sandboxie, debuggers, and security-tool DLLs, alongside timestamp tampering, file deletion, runtime unpacking, and direct or indirect system calls designed to complicate detection.

The malware contacts campaign infrastructure at 212.193.30.29 to request server.txt and at 212.193.30.45 to retrieve proxies.txt.

The first host is linked to a web-based operator platform called STANDOFF COORD, while the second is associated with proxy-list distribution.

MITRE ATT&CK techniques observed during sample execution, as mapped by the VMRay Platform (Source: vmray)
MITRE ATT&CK techniques observed during sample execution, as mapped by the VMRay Platform (Source: vmray)

STANDOFF COORD appears designed for multi-operator intrusions into enterprise environments.

Its recovered interface includes target inventories, agent check-ins, credential storage, evidence uploads, task management, shared playbooks, and tracking for passwords, NTLM hashes, Kerberos tickets, API tokens, cookies, and private keys.

The platform also organizes targets by internal, DMZ, and external network segments

The proxy-related infrastructure uses a deceptive redirection pattern: many servers return an HTTP 301 redirect to github.com, making routine scans appear less suspicious.

VMRay stressed that GitHub is not compromised; the threat actors are using its trusted domain as a redirect destination to obscure their own infrastructure.

Indicators of Compromise

IOC TypeIndicatorDescription
File namesetupx86x64install.exeInitial NSIS-based pay-per-install loader
MD5e77221d7a4b47b9107ba1b61a551ca89Loader sample hash
SHA-195c5ae3fec0d900e4634e11b3ad81971e78e2b31Loader sample hash

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories