AUTO-UPDATED

Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks

The Russian state-sponsored hacking group Turla is deploying a sophisticated .NET backdoor called STOCKSTAY to target government and military organizations in Ukraine and various European diplomatic entities.

Key Points

  • STOCKSTAY is a modular Windows backdoor that mimics legitimate software like PDF viewers and calculators to evade detection.
  • The malware utilizes a multi-component architecture, including a proxy-aware tunneler and a controller that manages command-and-control communications via secure WebSockets.
  • Google Threat Intelligence Group identified significant functional and code overlaps between STOCKSTAY and the long-standing Turla implant known as Kazuar.
  • Attackers distribute the malware through phishing campaigns, malicious RDP files, and exploits targeting a known WinRAR vulnerability, CVE-2025-8088.
  • The backdoor supports extensive post-exploitation capabilities, including file manipulation, screen capturing, and Windows Registry modification.

Why it Matters

This discovery highlights the ongoing evolution of Turla’s cyber espionage toolkit and their continued focus on high-value government and military targets. The use of STOCKSTAY alongside established tools like Kazuar suggests the group is actively testing new infrastructure to maintain persistent access within compromised networks.
Internet Published by info@thehackernews.com (The Hacker News)
Read original