threat-intel
Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets
High
Summary
Russia-linked APT Turla has been deploying a new .NET backdoor, dubbed StockStay, to conduct ongoing cyber espionage against Ukrainian government and military organizations, as well as entities with interests in Italian foreign policy. The backdoor utilizes deception techniques, masquerading as legitimate tools like stock market viewers and PDF readers, and relies on a complex command-and-control infrastructure. This activity highlights Turla’s persistent threat and its targeting of critical infrastructure within Ukraine and Europe.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data