← Back to Feed

STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus

June 25, 2026 · Google Cloud Security · Severity: HIGH

This article presents an in-depth analysis of STOCKSTAY, a .NET backdoor deployed by the Turla threat actor for cyber espionage against Ukrainian and Italian targets. It highlights the tool's continuous development and its similarities to the previously known KAZUAR toolkit.

Key Takeaways

  • STOCKSTAY is a .NET backdoor used by Russia-linked Turla since 2022.
  • It targets Ukrainian government and military, plus Italian foreign policy entities.
  • The backdoor shares significant code and functional overlaps with KAZUAR.
☕ Buy a Coffee