Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus

Google's deep-dive into Turla's evolving .NET backdoor STOCKSTAY gives SOC teams fresh detection signatures for a Russia-linked APT that persistently targets European government and diplomatic networks.

Summary written by editorial AI · Source link below

Filed by Google Threat Intel1 min readRead at source ↗

Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. Used for ongoing cyb

Editorial Analysis

Why it matters

Turla remains one of the most persistent espionage threats to European governments and critical infrastructure; updated IOCs from GTIG enable immediate detection improvements.

What to do

Ingest STOCKSTAY IOCs and YARA rules from the GTIG report into SIEM/EDR and hunt for .NET-based persistence in diplomatic or public-sector environments.

Board brief

Russia-linked Turla continues evolving espionage tools targeting European institutions — fresh intelligence enables proactive defence.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at Google Threat Intel

External link — opens at Google Threat Intel in a new tab.

§
Continue with

More from the Threat Intel Desk