logo

STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus

ID: e102377f-bef4-5a33-879c-2022593b6d53

STIX ID: report--e102377f-bef4-5a33-879c-2022593b6d53

Feed Name: Google Cloud Threat Intelligence

Threat Score
88/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

Author: Google Threat Intelligence Group

...
...

#### Executive summary: This GTIG report details the STOCKSTAY malware ecosystem — a multi-component, .NET-based toolkit used in phishing campaigns (notably via malicious RDP files) targeting Ukrainian government and military organizations and, to a lesser extent, European entities. The report describes operational techniques (environmental keying, staged deployments, use of compromised infrastructure), technical links and tool-sharing with the KAZUAR ecosystem (shared obfuscation primitives and componentized architecture), and provides a development timeline and IOCs to assist detection and hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.