home.social

#glupteba — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #glupteba, aggregated by home.social.

  1. Operation STANDOFF: A Campaign Hiding C2 Behind GitHub Redirects

    VMRay Labs uncovered a sophisticated Russian-speaking cybercriminal operation combining multiple attack vectors on shared infrastructure. The campaign distributes commodity stealers including Raccoon, RedLine, Amadey, SmokeLoader, Socelars, and Glupteba through a pay-per-install loader while enrolling victims into a proxy-botnet. Command-and-control servers on Russian provider TimeWeb use GitHub domain redirects for concealment. A custom multi-operator console called STANDOFF COORD coordinates hands-on-keyboard intrusions targeting Active Directory environments, storing NTLM hashes, Kerberos tickets, and credentials organized by network segments. Additionally, the infrastructure hosts an AI-driven influence operation using industrial-scale Telegram account farms and automated engagement platforms targeting Russian-speaking mobile gaming communities through a portal called Mobile Arena, driving traffic toward gambling sites and malware distribution.

    Pulse ID: 6a5f5a54ab92617993537c0b
    Pulse Link: otx.alienvault.com/pulse/6a5f5
    Pulse Author: AlienVault
    Created: 2026-07-21 11:39:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Amadey #CyberSecurity #GitHub #Glupteba #InfoSec #Malware #OTX #OpenThreatExchange #Proxy #RAT #RedLine #Russia #Telegram #bot #botnet #AlienVault

  2. Operation STANDOFF: A Campaign Hiding C2 Behind GitHub Redirects

    VMRay Labs uncovered a sophisticated Russian-speaking cybercriminal operation combining multiple attack vectors on shared infrastructure. The campaign distributes commodity stealers including Raccoon, RedLine, Amadey, SmokeLoader, Socelars, and Glupteba through a pay-per-install loader while enrolling victims into a proxy-botnet. Command-and-control servers on Russian provider TimeWeb use GitHub domain redirects for concealment. A custom multi-operator console called STANDOFF COORD coordinates hands-on-keyboard intrusions targeting Active Directory environments, storing NTLM hashes, Kerberos tickets, and credentials organized by network segments. Additionally, the infrastructure hosts an AI-driven influence operation using industrial-scale Telegram account farms and automated engagement platforms targeting Russian-speaking mobile gaming communities through a portal called Mobile Arena, driving traffic toward gambling sites and malware distribution.

    Pulse ID: 6a5f5a54ab92617993537c0b
    Pulse Link: otx.alienvault.com/pulse/6a5f5
    Pulse Author: AlienVault
    Created: 2026-07-21 11:39:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Amadey #CyberSecurity #GitHub #Glupteba #InfoSec #Malware #OTX #OpenThreatExchange #Proxy #RAT #RedLine #Russia #Telegram #bot #botnet #AlienVault