STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
Google's deep-dive into Turla's evolving .NET backdoor STOCKSTAY gives SOC teams fresh detection signatures for a Russia-linked APT that persistently targets European government and diplomatic networks.
Summary written by editorial AI · Source link below
Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. Used for ongoing cyb
Editorial Analysis
Turla remains one of the most persistent espionage threats to European governments and critical infrastructure; updated IOCs from GTIG enable immediate detection improvements.
Ingest STOCKSTAY IOCs and YARA rules from the GTIG report into SIEM/EDR and hunt for .NET-based persistence in diplomatic or public-sector environments.
Russia-linked Turla continues evolving espionage tools targeting European institutions — fresh intelligence enables proactive defence.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Google Threat Intel in a new tab.
More from the Threat Intel Desk
- Attackers Combo Up Evasion Tactics for BEC Phishing20 Jul
- New HollowGraph malware uses Microsoft Graph for stealthy C2 comms20 Jul
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign20 Jul
- Hackers were inside South Korea's diplomat training system for 9 months20 Jul
- Romania races to restore land registry after cyberattack disrupts property market20 Jul