Turla deploys .NET backdoor STOCKSTAY in espionage campaigns against Ukraine and Italian-linked interests

Colleagues, an important cyber note: Google details the .NET backdoor STOCKSTAY used by Turla against Ukrainian government entities and Italy‑linked interests.
- Multi‑component Windows family (MARKETMAKER, STOCKBROKER, STOCKTRADER, STOCKMARKET) with secured WebSocket and IPC.
- Distributed via phishing (including RDP files), RAR exploiting CVE‑2025‑8088, MSI, HTA and compromised WordPress sites.
- Shares architecture with Kazuar; used for initial access and post‑exploitation.
Why it matters: targeted, multi‑stage operations require monitoring WebSocket C2, archiving controls and .NET application inspections.
How are you preparing for such threats?
#cybersecurity #APT #malware #incident

