news.mlab.sh
Back to the feed
threat-intel

Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks

High
Image: The Hacker News
Summary

Google Threat Intelligence Group (GTIG) has identified a new backdoor, STOCKSTAY, developed and deployed by the Russian state-sponsored threat actor Turla. This multi-component backdoor, built using .NET and leveraging a WebSocket connection, has been used to target Ukrainian government and military organizations, as well as entities with interests in Italian foreign policy. The tool’s sophisticated design, including mimicking legitimate applications and utilizing a multi-hop C2 infrastructure, highlights Turla’s ongoing espionage activities.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.