Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets

General News

Summary

Google Threat Intelligence Group details a new Turla backdoor called StockStay that targets Ukrainian government and military organizations. The malware uses .NET components, disguises itself as productivity tools, and relies on phishing, malicious archives, and compromised infrastructure for delivery. The campaign also shows overlap with earlier Turla tooling and includes espionage features such as file exfiltration, screen capture, and system reconnaissance. The report highlights ongoing Russian cyberespionage activity against public-sector and diplomatic targets across Europe.

Classifications

industries
HealthTech
applications
Web and Content Management

AI Classifications

Labels
SaaS Consumer Software Enterprise Software

Linked Companies

Google LLC
$100M to $250M