Threats · 80 days ago
Turla is not treating each backdoor as a fresh project. It is carrying code and capabilities forward, which lets the group keep the same espionage tradecraft alive under new names and makes family-based detection too narrow.
Google Threat Intelligence Group says STOCKSTAY has been developed and deployed since at least December 2022, and has been used against Ukrainian government and military targets and entities tied to Italian foreign policy. GTIG also says it shares major code and function overlap with KAZUAR, a Turla toolkit already tied to past espionage activity.
The practical risk is a reusable platform that can move between campaigns without looking like a one-off sample. That gives defenders less value from chasing a single malware name and more reason to track the behavior set Turla keeps reusing.
4 sources covering this story
The Record from Recorded Future
Turla group adds more malware to Russia’s espionage efforts against Ukraine
Threat intelligence researchers at Google described StockStay, the latest malware developed by the Russian cyber-espionage group known as Turla.
Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks
Google links Turla to STOCKSTAY, a new .NET backdoor used in phishing attacks against Ukraine government and military targets.
Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets
Turla has been using the backdoor against government and military organizations in Ukraine for espionage.
The Latest Addition to Turla’s Intelligence Gathering Apparatus | Google Cloud Blog
Analysis of a backdoor, STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla.
Part of the PlainSec briefing for 2026-06-27