Google says the Russia-linked Turla hacking group has been using a newly detailed backdoor called StockStay to spy on government and military organizations in Ukraine. The .NET malware, developed since 2022, overlaps with Turla’s Kazuar implant and was delivered through phishing emails, malicious RDP configuration files, and in one November 2025 case a WinRAR exploit chain using CVE-2025-8088. Google also says compromised Ukrainian infrastructure and diplomacy- or education-themed lures were used in the campaign.
Why it matters: This is an active espionage campaign against wartime government and defense targets, with tactics defenders can hunt for now. Ukrainian and European public-sector organizations should review phishing defenses, inspect for StockStay-related persistence and WebSocket command-and-control traffic, and investigate any exposure to the cited WinRAR exploit chain.
2026.06.26
97% relevant
This is the same underlying event: Google's disclosure that Turla used the StockStay malware against Ukrainian government and military organizations. The article adds details on StockStay's development since at least December 2022, its code similarities to Kazuar, its evolution from a fake stock app to PDF reader and calculator disguises, and phishing delivery via malicious Remote Desktop Protocol configuration files sent with academic and diplomatic lures, including abuse of a compromised Ukrainian university account and a diplomatic education platform.
Ionut Arghire
2026.06.26
100% relevant
This article establishes a distinct campaign centered on Turla’s StockStay malware, its Ukraine-focused targeting, and its delivery methods; it is not the same underlying event as any listed tracked story.
← Back to all stories