Executive Summary
In June 2026, Google's Threat Intelligence Group identified a new .NET backdoor named STOCKSTAY, attributed to the Russian state-sponsored group Turla. This malware has been deployed against government and military organizations in Ukraine and entities interested in Italian foreign policy. STOCKSTAY, developed since at least December 2022, shares significant code and functional overlaps with Turla's previous implant, Kazuar. The backdoor comprises multiple components that communicate via inter-process communication channels and utilize secure WebSocket connections for command-and-control communication. It supports various commands, including file manipulation, system information gathering, and screen capture. (cloud.google.com)
The discovery of STOCKSTAY underscores the evolving sophistication of state-sponsored cyber espionage tools. Its deployment highlights the persistent threat posed by advanced persistent threats (APTs) like Turla, emphasizing the need for robust cybersecurity measures and continuous monitoring to protect sensitive governmental and military information.
Why This Matters Now
The emergence of STOCKSTAY reflects a significant advancement in Turla's cyber capabilities, indicating a heightened risk of sophisticated espionage operations targeting critical infrastructure. Organizations must prioritize enhancing their cybersecurity defenses to mitigate potential breaches and data exfiltration.
Attack Path Analysis
Turla initiated the attack by delivering phishing emails containing malicious RDP configuration files to Ukrainian government and military organizations. Upon execution, these files installed the STOCKSTAY backdoor, granting initial access. The backdoor's modular design allowed Turla to escalate privileges and execute commands, facilitating lateral movement within the network. STOCKSTAY established encrypted WebSocket connections to Turla's command-and-control servers, enabling remote control. The malware's capabilities, such as file exfiltration and screen capture, were utilized to gather and exfiltrate sensitive information. The primary impact was the unauthorized access and exfiltration of confidential government and military data.
Kill Chain Progression
Initial Compromise
Description
Turla delivered phishing emails with malicious RDP configuration files to Ukrainian government and military organizations, leading to the installation of the STOCKSTAY backdoor upon execution.
MITRE ATT&CK® Techniques
Command and Scripting Interpreter: Visual Basic
Application Layer Protocol: Web Protocols
Encrypted Channel: Symmetric Cryptography
Masquerading: Match Legitimate Name or Location
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Ingress Tool Transfer
Obfuscated Files or Information
Input Capture: Keylogging
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Malware Protection
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Direct targeting by Turla's STOCKSTAY backdoor against Ukrainian government entities creates critical espionage risks requiring enhanced east-west traffic security and zero trust segmentation.
Defense/Space
Military organizations face state-sponsored .NET backdoor attacks enabling lateral movement and data exfiltration, demanding encrypted traffic protection and egress security enforcement.
International Affairs
Entities with Italian foreign policy interests targeted by Russian APT require multicloud visibility, threat detection capabilities, and secure hybrid connectivity protection.
Information Technology/IT
IT infrastructure supporting targeted sectors vulnerable to STOCKSTAY's command and control capabilities, necessitating cloud firewall protection and inline intrusion prevention systems.
Sources
- Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attackshttps://thehackernews.com/2026/06/google-details-turlas-new-stockstay.htmlVerified
- Russian APT Deploys 'StockStay' Backdoor Against Ukrainian Targetshttps://www.securityweek.com/russian-apt-deploys-stockstay-backdoor-against-ukrainian-targets/Verified
- STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatushttps://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering/Verified
- Russian hackers test new virus targeting Ukraine and EU authoritieshttps://newsukraine.rbc.ua/news/russian-hackers-test-new-virus-targeting-1782476470.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The initial compromise may have been contained to the targeted workload, reducing the potential for the attacker to access other systems.
Control: Zero Trust Segmentation
Mitigation: Privilege escalation attempts could have been constrained, limiting the attacker's ability to gain higher-level access within the compromised system.
Control: East-West Traffic Security
Mitigation: Lateral movement may have been restricted, reducing the attacker's ability to access additional systems within the network.
Control: Multicloud Visibility & Control
Mitigation: Command and control communications could have been detected and potentially disrupted, limiting the attacker's remote control capabilities.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts may have been identified and restricted, reducing the amount of sensitive information leaving the network.
The overall impact of the attack could have been mitigated, limiting the scope of data loss and operational disruption.
Impact at a Glance
Affected Business Functions
- Government Communications
- Military Operations
- Foreign Policy Decision-Making
Estimated downtime: 7 days
Estimated loss: N/A
Potential exposure of sensitive government and military documents, including foreign policy information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement robust email filtering and user training to mitigate phishing attacks.
- • Deploy endpoint detection and response (EDR) solutions to identify and block malicious RDP configurations.
- • Utilize network segmentation to limit lateral movement within the network.
- • Enforce strict egress filtering to prevent unauthorized outbound connections.
- • Regularly update and patch systems to reduce vulnerabilities exploited by malware.



