STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
Google's deep-dive into Turla's evolving .NET backdoor STOCKSTAY gives SOC teams fresh detection signatures for a Russia-linked APT that persistently targets European government and diplomatic networks.
Summary written by editorial AI · Source link below
Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. Used for ongoing cyb
Editorial Analysis
Turla remains one of the most persistent espionage threats to European governments and critical infrastructure; updated IOCs from GTIG enable immediate detection improvements.
Ingest STOCKSTAY IOCs and YARA rules from the GTIG report into SIEM/EDR and hunt for .NET-based persistence in diplomatic or public-sector environments.
Russia-linked Turla continues evolving espionage tools targeting European institutions — fresh intelligence enables proactive defence.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Google Threat Intel in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner2d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d