Security · 2h ago
Google Links Russian Turla Group to New STOCKSTAY Backdoor in Ukraine
Google Threat Intelligence attributes the STOCKSTAY .NET backdoor to Russia's Turla group, targeting Ukrainian government and military entities. The malware also hit organizations with Italian foreign policy interests. Turla continues to develop the Windows backdoor for espionage operations.
Meridian48 take
This attribution underscores Turla's persistent focus on Ukraine and European policy targets, but the novelty of STOCKSTAY may be overstated given Turla's established toolkit.
Read the full reporting
Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks →
The Hacker News
turlastockstay-backdoor