Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets
Summary
Google Threat Intelligence Group details a new Turla backdoor called StockStay that targets Ukrainian government and military organizations. The malware uses .NET components, disguises itself as productivity tools, and relies on phishing, malicious archives, and compromised infrastructure for delivery. The campaign also shows overlap with earlier Turla tooling and includes espionage features such as file exfiltration, screen capture, and system reconnaissance. The report highlights ongoing Russian cyberespionage activity against public-sector and diplomatic targets across Europe.
Classifications
industries
HealthTech
applications
Web and Content Management
AI Classifications
Labels
SaaS
Consumer Software
Enterprise Software
Linked Companies
Google LLC
$100M to $250M