threat-intel
Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks
High
Summary
Google Threat Intelligence Group (GTIG) has identified a new backdoor, STOCKSTAY, developed and deployed by the Russian state-sponsored threat actor Turla. This multi-component backdoor, built using .NET and leveraging a WebSocket connection, has been used to target Ukrainian government and military organizations, as well as entities with interests in Italian foreign policy. The tool’s sophisticated design, including mimicking legitimate applications and utilizing a multi-hop C2 infrastructure, highlights Turla’s ongoing espionage activities.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
