Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Unit 42 reports that CL-STA-1062 is actively targeting government entities and critical infrastructure in Southeast Asia for espionage purposes. The threat actor employs a hybrid toolkit that includes a custom backdoor called TinyRCT. The ongoing campaign underscores the persistent cyber espionage threat facing government networks in the region.
Unit 42 reports that CL-STA-1062 is actively targeting government entities and critical infrastructure in Southeast Asia for espionage purposes. The threat actor employs a hybrid toolkit that includes a custom backdoor called TinyRCT. The ongoing campaign underscores the persistent cyber espionage threat facing government networks in the region.
This article presents an in-depth analysis of STOCKSTAY, a .NET backdoor deployed by the Turla threat actor for cyber espionage against Ukrainian and Italian targets. It highlights the tool's continuous development and its similarities to the previously known KAZUAR toolkit.
Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a.NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR,...
Google Threat Intelligence Group's in-depth analysis of STOCKSTAY reveals a continuously developed .NET backdoor used by the Russia-linked Turla APT group as part of its intelligence gathering apparatus. The malware represents the group's ongoing investment in covert collection capabilities.
This article presents an in-depth analysis of STOCKSTAY, a .NET backdoor deployed by the Turla threat actor for cyber espionage against Ukrainian and Italian targets. It highlights the tool's continuous development and its similarities to the previously known KAZUAR toolkit.