OFICIAL Google Cloud Threat Intelligence

The Latest Addition to Turla’s Intelligence Gathering Apparatus

What happened
Based on Google Cloud Threat Intelligence · Jun 25, 2026

Google’s threat intelligence team has detailed STOCKSTAY, a new .NET backdoor attributed to the Russian cyber espionage group Turla, active since late 2022 and targeting Ukrainian government and military entities as well as Italian foreign policy interests.

The Latest Addition to Turla’s Intelligence Gathering Apparatus
Google Cloud Threat Intelligence — Google
Key points
·
Visibility and context on the threats that matter most.
·
Turla has deployed STOCKSTAY against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy.
·
Used for ongoing cyber espionage, this backdoor shares significant code and functional overlaps with KAZUAR, a successful toolkit previously attributed to Turla.
·
The group has a long history of targeting a wide range of industries, with a particular focus on western Ministries of Foreign Affairs, and defense organizations within the context of heightened political tensions.

Google Cloud Threat Intelligence Group (GTIG) has published an analysis of STOCKSTAY, a .NET backdoor deployed by the Russia-linked Turla group since December 2022. The malware has been used in cyber espionage operations against government and military targets in Ukraine and entities linked to Italian foreign policy. Turla, also known as SUMMIT or Secret Blizzard, has a history of targeting western Ministries of Foreign Affairs and defense organizations, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) attributing the group to Russia’s Federal Security Service (FSB) Center 16.

STOCKSTAY operates as a multi-component backdoor written in .NET, using Windows Forms and communicating via secure WebSocket connections. It disguises itself as legitimate applications, such as stock market tools, PDF viewers, or calculator utilities, to evade detection. The malware’s components include STOCKSTAY.STOCKBROKER, which relays encrypted communications to command-and-control servers, and STOCKSTAY.STOCKMARKET, which manages configuration and encryption using a 4096-bit RSA key pair.

The STOCKSTAY.STOCKTRADER component functions as the primary backdoor, enabling registry manipulation, file operations, command execution, directory listing, and screen capture on infected hosts. It can delete files, generate directory listings, retrieve files with specific extensions, and archive collected data for exfiltration. The malware also supports creating directories, executing serialized JSON tasks, and appending content to files, with all operations reported back to the command-and-control server.

GTIG’s analysis highlights Turla’s evolving tactics, including the reuse of code from the KAZUAR toolkit and the deployment of specialized scripts to intercept Signal Messenger communications. The group has also hijacked legacy criminal botnets to target Ukrainian organizations, demonstrating persistent adaptability in its cyber espionage campaigns.

Original source → Deals on Clipraptor.com →