Threats & Adversaries · APT / Espionage
Turla Reuses KAZUAR to Extend Its Espionage Platform Turla is not treating each backdoor as a fresh project. It is carrying code and capabilities forward, which lets the group keep the same espionage tradecraft alive under new names and makes family-based detection too narrow.
Google Threat Intelligence Group says STOCKSTAY has been developed and deployed since at least December 2022, and has been used against Ukrainian government and military targets and entities tied to Italian foreign policy. GTIG also says it shares major code and function overlap with KAZUAR, a Turla toolkit already tied to past espionage activity.
The practical risk is a reusable platform that can move between campaigns without looking like a one-off sample. That gives defenders less value from chasing a single malware name and more reason to track the behavior set Turla keeps reusing.
4 sources · Jun 26
Timeline Sources Jun 26 The Record from Recorded Future
Turla group adds more malware to Russia’s espionage efforts against Ukraine
Threat intelligence researchers at Google described StockStay, the latest malware developed by the Russian cyber-espionage group known as Turla.
original Jun 26 The Hacker News
Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks
Google links Turla to STOCKSTAY, a new .NET backdoor used in phishing attacks against Ukraine government and military targets.
original Jun 26 SecurityWeek
Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets
Turla has been using the backdoor against government and military organizations in Ukraine for espionage.
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-06-26
Every edition of this story: Turla Reuses KAZUAR to Extend Its Espionage Platform
More from today
Threats & Adversaries · APT / Espionage
Turla Reuses KAZUAR to Extend Its Espionage Platform Turla is not treating each backdoor as a fresh project. It is carrying code and capabilities forward, which lets the group keep the same espionage tradecraft alive under new names and makes family-based detection too narrow.
Google Threat Intelligence Group says STOCKSTAY has been developed and deployed since at least December 2022, and has been used against Ukrainian government and military targets and entities tied to Italian foreign policy. GTIG also says it shares major code and function overlap with KAZUAR, a Turla toolkit already tied to past espionage activity.
The practical risk is a reusable platform that can move between campaigns without looking like a one-off sample. That gives defenders less value from chasing a single malware name and more reason to track the behavior set Turla keeps reusing.
4 sources · Jun 26
Timeline Sources Jun 26 The Record from Recorded Future
Turla group adds more malware to Russia’s espionage efforts against Ukraine
Threat intelligence researchers at Google described StockStay, the latest malware developed by the Russian cyber-espionage group known as Turla.
original Jun 26 The Hacker News
Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks
Google links Turla to STOCKSTAY, a new .NET backdoor used in phishing attacks against Ukraine government and military targets.
original Jun 26 SecurityWeek
Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets
Turla has been using the backdoor against government and military organizations in Ukraine for espionage.
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-06-26
Every edition of this story: Turla Reuses KAZUAR to Extend Its Espionage Platform
More from today