The Russian state-sponsored hacking group Turla is deploying a sophisticated .NET backdoor called STOCKSTAY to target government and military organizations in Ukraine and various European diplomatic entities.
Key Points
- STOCKSTAY is a modular Windows backdoor that mimics legitimate software like PDF viewers and calculators to evade detection.
- The malware utilizes a multi-component architecture, including a proxy-aware tunneler and a controller that manages command-and-control communications via secure WebSockets.
- Google Threat Intelligence Group identified significant functional and code overlaps between STOCKSTAY and the long-standing Turla implant known as Kazuar.
- Attackers distribute the malware through phishing campaigns, malicious RDP files, and exploits targeting a known WinRAR vulnerability, CVE-2025-8088.
- The backdoor supports extensive post-exploitation capabilities, including file manipulation, screen capturing, and Windows Registry modification.