Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Turla group deploys new STOCKSTAY backdoor against Ukraine and Italy

The Russian state-sponsored Turla group is deploying a new .NET backdoor called STOCKSTAY for cyber espionage against Ukrainian and Italian targets. Initial infection vectors include phishing emails with malicious RAR archives exploiting WinRAR vulnerabilities and RDP files. The modular malware communicates via secure WebSockets and shares significant code overlap with the group's older Kazuar backdoor.
Read Full Article →

Threat Intelligence Turla group deploys new STOCKSTAY backdoor against Ukraine and Italy June 26, 2026 Share By SC Staff A new .NET backdoor, dubbed STOCKSTAY, has been attributed to the Russian state-sponsored threat actor Turla, according to the Google Threat Intelligence Group. This sophisticated cyber espionage tool has been deployed against government and military organizations in Ukraine, as well as entities with interests in Italian foreign policy, according to a recent report by The Hacker News. STOCKSTAY, written in .NET and utilizing the Windows Forms framework, communicates with its command-and-control (C2) server via a secure WebSocket connection. It shares significant code and functional overlaps with Kazuar, a backdoor previously used by Turla since 2017. The malware is multi-component, with distinct modules like STOCKSTAY.STOCKBROKER for tunneling and STOCKSTAY.STOCKTRADER for information gathering, all orchestrated by STOCKSTAY.STOCKMARKET. Initial infection vectors have included phishing emails with malicious RDP files and RAR archives exploiting WinRAR vulnerabilities. Turla has used STOCKSTAY both for initial access and during post-exploitation phases, sometimes alongside Kazuar, suggesting potential testing of new capabilities or a transition from older tools. The targeting of Ukrainian and Italian entities highlights the ongoing cyber espionage efforts by the group. Source: The Hacker News SC Staff Related Threat Intelligence Russian hackers suspected in Jaguar Land Rover cyberattack SC Staff June 26, 2026 The cyberattack on Jaguar Land Rover (JLR), a major UK employer, caused production to halt for months, resulting in an estimated $2.5 billion loss to the British economy and necessitating a £1.5 billion government bailout. Threat Intelligence Sports piracy ring linked to PirloTV disrupted in 44-domain takedown SC Staff June 25, 2026 The Alliance for Creativity and Entertainment (ACE), in collaboration with UEFA, UC3, and Mexican authorities, successfully shut down 44 domains linked to PirloTV. Threat Intelligence Russia reportedly hacked dissident’s phone with Cellebrite tools after company cut ties SC Staff June 25, 2026 The report by The Citizen Lab found evidence that a Russian government investigative unit used Cellebrite's UFED tool to access the iPhone of opposition politician Andrey Pivovarov in June 2021. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Account Harvesting Backdoor Deauthentication Attack Denial of Service Dictionary Attack Distributed Scans Dumpster Diving Hybrid Attack Information Warfare Password Cracking You can skip this ad in 5 seconds

Share this article