← Back to Feed

STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus

June 25, 2026 · Google Cloud Security · Severity: MEDIUM

Google Threat Intelligence Group's in-depth analysis of STOCKSTAY reveals a continuously developed .NET backdoor used by the Russia-linked Turla APT group as part of its intelligence gathering apparatus. The malware represents the group's ongoing investment in covert collection capabilities. Turla continues to adapt STOCKSTAY for long-term espionage operations.

Key Takeaways

  • STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus — Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an...
  • Android RATs distributed through fake apps pose significant mobile security risks requiring app-store vigilance.
  • Staying informed on emerging threats is key to maintaining a strong security posture.
  • Regular security awareness training and layered defenses remain the foundation of any effective cybersecurity program.
☕ Buy a Coffee