CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Permanent story citation

STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 305

As cited

Citation snapshot as of .

threat intel

STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus

Google Threat Intelligence Group identified STOCKSTAY, a .NET backdoor developed by Russia-linked threat actor Turla since at least December 2022, deployed against Ukrainian government and military organizations as well as entities with Italian foreign policy interests. The multi-component malware communicates via secure WebSocket connections and shares significant code overlap with Turla's previously known KAZUAR toolkit. STOCKSTAY variants have evolved to masquerade as benign applications including stock market viewers, PDF readers, and calculators.

Why it matters: Organizations in government, military, and foreign affairs sectors should assess their defensive posture against this actively developed espionage platform and its overlapping code base with KAZUAR.

Source published
First seen by Cybersecurity Tracker

Source attribution