VMTech
Discuss a project

Turla deploys .NET backdoor STOCKSTAY in espionage campaigns against Ukraine and Italian-linked interests

Turla deploys .NET backdoor STOCKSTAY in espionage campaigns against Ukraine and Italian-linked interests

Colleagues, an important cyber note: Google details the .NET backdoor STOCKSTAY used by Turla against Ukrainian government entities and Italy‑linked interests.

- Multi‑component Windows family (MARKETMAKER, STOCKBROKER, STOCKTRADER, STOCKMARKET) with secured WebSocket and IPC.
- Distributed via phishing (including RDP files), RAR exploiting CVE‑2025‑8088, MSI, HTA and compromised WordPress sites.
- Shares architecture with Kazuar; used for initial access and post‑exploitation.

Why it matters: targeted, multi‑stage operations require monitoring WebSocket C2, archiving controls and .NET application inspections.

How are you preparing for such threats?

#cybersecurity #APT #malware #incident

Open analytics
On the site 0 views
min read 1 28.06.2026
Instagram

Turla deploys .NET backdoor STOCKSTAY in espionage campaigns against Ukraine and Italian-linked interests

Open the post on Instagram ↗