As cited
Citation snapshot as of .
threat intel
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
Google Threat Intelligence Group identified STOCKSTAY, a .NET backdoor developed by Russia-linked threat actor Turla since at least December 2022, deployed against Ukrainian government and military organizations as well as entities with Italian foreign policy interests. The multi-component malware communicates via secure WebSocket connections and shares significant code overlap with Turla's previously known KAZUAR toolkit. STOCKSTAY variants have evolved to masquerade as benign applications including stock market viewers, PDF readers, and calculators.
Why it matters: Organizations in government, military, and foreign affairs sectors should assess their defensive posture against this actively developed espionage platform and its overlapping code base with KAZUAR.
- Source published
- First seen by Cybersecurity Tracker