Stantinko is a long-running modular malware ecosystem and botnet active since at least 2012, primarily associated with financially motivated operations targeting Windows systems, with additional Linux components observed. It has been especially prevalent in Russia and Ukraine, with further activity affecting Belarus and Kazakhstan. The operation is best known for monetizing infections through malicious browser extensions that perform ad injection, traffic redirection, and click fraud, but it also functions as a stealthy backdoor platform capable of delivering additional modules for broader criminal use.
On Windows, Stantinko commonly arrives through fake or pirated software installers, including downloader chains that masquerade as cracked applications or torrent-style packages. Its installation flow has included intermediary components such as FileTour and Adstantinko, which deploy persistent services that can reinstall one another if removed. Stantinko uses custom obfuscation, encrypted components, registry-stored payload material, per-infection decryption logic, and in-memory plugin execution to hinder analysis and cleanup.
A major feature of the ecosystem is installation of malicious browser extensions, notably The Safe Surfing and Teddy Protection, which were presented as benign protective tools but were used to inject advertisements, replace or intercept search-engine links, redirect users through affiliate and advertising flows, and support click-fraud monetization. These extensions also incorporated anti-analysis and persistence-related behavior, including self-removal under certain inspection conditions and reinstallation by other Stantinko components.
Stantinko has also supported a broad plugin set beyond ad fraud. Documented modules include a remote administration backdoor, a distributed Google search automation component, a brute-force tool targeting Joomla and WordPress administrator interfaces, a Facebook abuse bot, and a cryptomining module. The cryptominer, active since at least 2018, used a heavily modified and obfuscated variant of xmr-stak to mine Monero, retrieved proxy configuration indirectly through public web content, downloaded hashing code at runtime, and included logic to suspend competing miners and reduce visibility during user activity or analysis.
Linux-targeting components linked to Stantinko include Trojan proxy variants deployed on compromised servers. Observed Linux samples implemented authenticated SOCKS5 proxying or HTTP proxy behavior, reported host information to command infrastructure, could relay attacker traffic, and in earlier variants supported self-update or file-receipt functionality. Some evidence indicates these Linux infections were obtained through brute-force activity against web administration surfaces.
Overall, Stantinko is best characterized as a modular backdoor and botnet whose operators combined ad fraud, browser abuse, brute-force attacks, social-network fraud, credential theft, proxying, and cryptomining within a resilient and heavily obfuscated malware framework.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
we have discovered a new version of a Linux proxy trojan related to Stantinko group ... We have identified a new version of this Linux trojan masqueraded as httpd
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Another trick used to avoid detection is to hide the malicious code in the Windows Registry... In this family... the code responsible for the communication with the C&C is encrypted. However, it is stored in the Windows Registry instead of in a different DLL file.
Stantinko’s main functionality is to install malicious browser extensions named The Safe Surfing and Teddy Protection.
The scripts, written entirely in Python, deal with Stantinko's unique control-flow-flattening (CFF) and string obfuscation techniques
The scripts, written entirely in Python, deal with Stantinko's unique control-flow-flattening (CFF) and string obfuscation techniques
722 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as another malware example that also used control-flow flattening.
A Linux proxy trojan linked to the Stantinko group that masquerades as httpd, validates a local configuration file, daemonizes, listens for client connections, redirects benign GET requests to a configured URL, and forwards POST/NOTIFY traffic to attacker C2 paths to relay responses back to infected clients.
A botnet targeting Linux systems, used for ad fraud and click fraud operations.
Botnet associated with click fraud, ad injection, social network fraud, password stealing, and cryptomining. In this reference it is the malware family Stadeo was primarily built to analyze and deobfuscate.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.