logo

Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks

ID: dfd97583-2009-5cc9-a232-62bb949d50bd

STIX ID: report--dfd97583-2009-5cc9-a232-62bb949d50bd

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-06-26

Date Updated: 2026-06-26

Author: [email protected] (The Hacker News)

...
...

Google Threat Intelligence attributes a previously undocumented multi-component .NET backdoor named STOCKSTAY to the Turla APT, describing its downloader (MARKETMAKER), core modules (STOCKBROKER, STOCKTRADER, STOCKMARKET), WebSocket-based encrypted C2, IPC via WM_COPYDATA, and a broad set of espionage capabilities; the report details distribution vectors including phishing with malicious RDP/HTA/MSI, exploitation of CVE-2025-8088, use of compromised WordPress sites, overlaps with the Kazuar toolkit, and observed targeting of Ukrainian government and military organizations and entities tied to Italian foreign policy.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.