STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus

The Russia-linked threat actor Turla has developed a .NET backdoor, STOCKSTAY, used for cyber espionage. STOCKSTAY shares code and functional overlaps with KAZUAR, a successful toolkit previously attributed to Turla. Turla has targeted government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. This backdoor is part of Turla's evolving arsenal, which has been active since at least 2004. Engineers should be aware of this threat and take necessary precautions to protect their systems.

Source →
FeedLens — Signal over noise Last 7 days