Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks
ID: dfd97583-2009-5cc9-a232-62bb949d50bd
STIX ID: report--dfd97583-2009-5cc9-a232-62bb949d50bd
Feed Name: The Hacker News
Google Threat Intelligence attributes a previously undocumented multi-component .NET backdoor named STOCKSTAY to the Turla APT, describing its downloader (MARKETMAKER), core modules (STOCKBROKER, STOCKTRADER, STOCKMARKET), WebSocket-based encrypted C2, IPC via WM_COPYDATA, and a broad set of espionage capabilities; the report details distribution vectors including phishing with malicious RDP/HTA/MSI, exploitation of CVE-2025-8088, use of compromised WordPress sites, overlaps with the Kazuar toolkit, and observed targeting of Ukrainian government and military organizations and entities tied to Italian foreign policy.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
