discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks

Google's Threat Intelligence Group has detailed a new .NET backdoor called STOCKSTAY, used by Russian state-sponsored threat actor Turla in Ukraine espionage attacks. The backdoor has been deployed against government and military organizations in Ukraine and entities inte…

By Ravie Lakshmanan·Jun 26·thehackernews.com·2 min read

Intelligence analysis by Llama 3.3 70B

Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks
Image: thehackernews.com

STOCKSTAY is a multi-component backdoor that communicates with its command-and-control via a secure WebSocket connection, utilizing the open-source websocket-sharp library. It consists of several distinct components that communicate with one another via an inter-process communication channel.

Why it matters

The discovery of STOCKSTAY highlights the ongoing cyber espionage efforts of Russian state-sponsored threat actors, particularly Turla, and the need for government and military organizations to enhance their cybersecurity measures. The backdoor's ability to mimic harmless programs and its use of secure communication channels make it a significant threat.

Imagine a bad guy who wants to spy on a government computer. They use a special tool called STOCKSTAY to sneak into the computer and steal secrets. STOCKSTAY is like a master key that can open many doors, and it's very hard to detect. The bad guys use it to spy on governments and military organizations, and it's a big problem.

Analysis

Introduction to STOCKSTAY

The STOCKSTAY backdoor is a sophisticated cyber espionage tool that has been used by Turla in various attacks. It is a multi-component backdoor written in .NET, using the Windows Forms framework, and communicates with its command-and-control via a secure WebSocket connection. The backdoor consists of several distinct components that communicate with one another via an inter-process communication channel.

The STOCKSTAY backdoor is designed to mimic a stock market data viewing tool, but it has been adapted to masquerade as other harmless programs like PDF viewers and calculator utilities. This makes it difficult to detect and highlights the need for advanced cybersecurity measures.

Technical Details of STOCKSTAY

The STOCKSTAY backdoor has several components, including a downloader component codenamed STOCKSTAY.MARKETMAKER, a proxy-aware tunneler, and a main backdoor that enables information gathering. The backdoor also has an orchestrator or controller that parses the backdoor's configuration and sets several options regarding the malware's execution.

The STOCKSTAY backdoor has been used in various attacks, including phishing campaigns that target government and military organizations in Ukraine. The backdoor has also been used in attacks aimed at entities in Italy, the Netherlands, Poland, and Germany. The use of STOCKSTAY in these attacks highlights the ongoing cyber espionage efforts of Russian state-sponsored threat actors.

Implications of STOCKSTAY

The discovery of STOCKSTAY has significant implications for government and military organizations, particularly in Ukraine. It highlights the need for advanced cybersecurity measures, including the use of secure communication channels and the implementation of robust threat detection systems. The use of STOCKSTAY in various attacks also highlights the ongoing cyber espionage efforts of Russian state-sponsored threat actors and the need for increased cooperation between governments and cybersecurity experts to combat these threats.

Key points

  • STOCKSTAY is a .NET backdoor used by Russian state-sponsored threat actor Turla
  • The backdoor has been deployed against government and military organizations in Ukraine and entities interested in Italian foreign policy
  • STOCKSTAY consists of several distinct components that communicate with one another via an inter-process communication channel
The Upside

The discovery of STOCKSTAY highlights the importance of cybersecurity and the need for government and military organizations to enhance their cybersecurity measures. By understanding how STOCKSTAY works and how it is used, cybersecurity experts can develop more effective threat detection systems and protect against similar attacks in the future. This can lead to a reduction in cyber espionage attacks and a safer online environment.

The Downside

The use of STOCKSTAY in various attacks highlights the ongoing cyber espionage efforts of Russian state-sponsored threat actors and the need for increased cooperation between governments and cybersecurity experts to combat these threats. If left unchecked, these attacks can have significant consequences, including the theft of sensitive information and the disruption of critical infrastructure. The use of STOCKSTAY also highlights the need for advanced cybersecurity measures, including the use of secure communication channels and the implementation of robust threat detection systems.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritycyber-espionagerussiaukraine

Author

Ravie Lakshmanan

Intelligence analysis by

Llama 3.3 70B

Published

Jun 26, 2026

Source

thehackernews.com

Share

Topics

securitycyber-espionagerussiaukraine

Related

More from this desk

Aug 14·schneier.com

Upcoming Speaking Engagements

Bruce Schneier shares his upcoming speaking engagements, including LAcon V in Anaheim, California, USA, a League of Women Voters event, Elevate Festival in Toronto, Canada, CanSecWest 2026 in Vancouver, Canada, and ATTENTION: Democracy, Rebuilt in Montreal, Canada.

Aug 14·bleepingcomputer.com

Hackers Exploit macOS Screen Sharing Flaw to Deploy Monero Miner

NCSC warns of active macOS vulnerability exploitation for cryptocurrency mining.

Aug 14·bleepingcomputer.com

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

The article discusses the evolving attack chain in Google Workspace security, where OAuth tokens become the entry point for attackers, and AI agents are increasingly used to exploit vulnerabilities. The author argues that security teams need to rethink their defenses to a…

Aug 14·bleepingcomputer.com

Max severity SAP Commerce Cloud flaw now targeted in attacks

A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused.