Google Details Turla’s New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks
The Russian state-sponsored threat actor known as Turla has been ascribed to a previously unrecorded .STOCKSTAY is a NET backdoor that has been used against Ukrainian government and military institutions as well as groups with an interest in Italian foreign policy.
The Google Threat Intelligence outfit (GTIG) described the Windows backdoor as being continuously updated by the hacker outfit and stated that the cyber espionage weapon shares significant code and functional overlaps with Kazuar, a staple implant used by the adversary since 2017. Malware development activities has been suspected since December 2022.
According to GTIG, STOCKSTAY is a multi-component backdoor written in.NET using the Windows Forms architecture. It uses the open-source websocket-sharp library to establish a...

