Turla Reuses KAZUAR to Extend Its Espionage Platform

Turla is not treating each backdoor as a fresh project. It is carrying code and capabilities forward, which lets the group keep the same espionage tradecraft alive under new names and makes family-based detection too narrow. Google Threat Intelligence Group says STOCKSTAY has been developed and deployed since at least December 2022, and has been used against Ukrainian government and military targets and entities tied to Italian foreign policy. GTIG also says it shares major code and function overlap with KAZUAR, a Turla toolkit already tied to past espionage activity. The practical risk is a reusable platform that can move between campaigns without looking like a one-off sample. That gives defenders less value from chasing a single malware name and more reason to track the behavior set Turla keeps reusing.

Part of the PlainSec briefing for 2026-06-27

Sources