Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks
Google's Threat Intelligence Group has detailed a new .NET backdoor called STOCKSTAY, used by Russian state-sponsored threat actor Turla in Ukraine espionage attacks. The backdoor has been deployed against government and military organizations in Ukraine and entities inte…
Intelligence analysis by Llama 3.3 70B

STOCKSTAY is a multi-component backdoor that communicates with its command-and-control via a secure WebSocket connection, utilizing the open-source websocket-sharp library. It consists of several distinct components that communicate with one another via an inter-process communication channel.
Imagine a bad guy who wants to spy on a government computer. They use a special tool called STOCKSTAY to sneak into the computer and steal secrets. STOCKSTAY is like a master key that can open many doors, and it's very hard to detect. The bad guys use it to spy on governments and military organizations, and it's a big problem.
Analysis
Introduction to STOCKSTAY
The STOCKSTAY backdoor is a sophisticated cyber espionage tool that has been used by Turla in various attacks. It is a multi-component backdoor written in .NET, using the Windows Forms framework, and communicates with its command-and-control via a secure WebSocket connection. The backdoor consists of several distinct components that communicate with one another via an inter-process communication channel.
The STOCKSTAY backdoor is designed to mimic a stock market data viewing tool, but it has been adapted to masquerade as other harmless programs like PDF viewers and calculator utilities. This makes it difficult to detect and highlights the need for advanced cybersecurity measures.
Technical Details of STOCKSTAY
The STOCKSTAY backdoor has several components, including a downloader component codenamed STOCKSTAY.MARKETMAKER, a proxy-aware tunneler, and a main backdoor that enables information gathering. The backdoor also has an orchestrator or controller that parses the backdoor's configuration and sets several options regarding the malware's execution.
The STOCKSTAY backdoor has been used in various attacks, including phishing campaigns that target government and military organizations in Ukraine. The backdoor has also been used in attacks aimed at entities in Italy, the Netherlands, Poland, and Germany. The use of STOCKSTAY in these attacks highlights the ongoing cyber espionage efforts of Russian state-sponsored threat actors.
Implications of STOCKSTAY
The discovery of STOCKSTAY has significant implications for government and military organizations, particularly in Ukraine. It highlights the need for advanced cybersecurity measures, including the use of secure communication channels and the implementation of robust threat detection systems. The use of STOCKSTAY in various attacks also highlights the ongoing cyber espionage efforts of Russian state-sponsored threat actors and the need for increased cooperation between governments and cybersecurity experts to combat these threats.
Key points
- STOCKSTAY is a .NET backdoor used by Russian state-sponsored threat actor Turla
- The backdoor has been deployed against government and military organizations in Ukraine and entities interested in Italian foreign policy
- STOCKSTAY consists of several distinct components that communicate with one another via an inter-process communication channel
The discovery of STOCKSTAY highlights the importance of cybersecurity and the need for government and military organizations to enhance their cybersecurity measures. By understanding how STOCKSTAY works and how it is used, cybersecurity experts can develop more effective threat detection systems and protect against similar attacks in the future. This can lead to a reduction in cyber espionage attacks and a safer online environment.
The use of STOCKSTAY in various attacks highlights the ongoing cyber espionage efforts of Russian state-sponsored threat actors and the need for increased cooperation between governments and cybersecurity experts to combat these threats. If left unchecked, these attacks can have significant consequences, including the theft of sensitive information and the disruption of critical infrastructure. The use of STOCKSTAY also highlights the need for advanced cybersecurity measures, including the use of secure communication channels and the implementation of robust threat detection systems.


