www.securityweek.com 6/26/2026, 9:10:59 AM · external

Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets

Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets
Developing story campaign 2 articles tracked
Turla APT deploys StockStay backdoor against Ukrainian targets
CyberSIXT Evidence Panel
Primary Source cloud.google.com
Threat Actor

RUSSIA-LINKED APT Turla, also known as Krypton or Snake, is targeting Ukrainian government and military organizations with a new backdoor named StockStay. This .NET-based backdoor, under development since 2022, has been used for espionage activities, particularly against Ukrainian and Italian interests. StockStay masquerades as legitimate applications and uses secure WebSocket communication for command and control.

It features components such as a downloader and a tunneler for remote interactions and executes various commands including file manipulation and system information gathering. The group has also leveraged phishing tactics using compromised academic accounts to deploy this malware.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline