Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets

    June 28, 2026

    Tom Hanks Frets AI Could Voice Woody in Even More “Toy Story” Movies

    June 28, 2026

    Getting to Mars may require a pit stop in orbit, and NASA just tested the nozzle to make that happen

    June 28, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets
    Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets
    Cybersecurity

    Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets

    The Tech GuyBy The Tech GuyJune 28, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Russia-linked APT Turla has been targeting government and military organizations in Ukraine with a new backdoor specifically designed for espionage, Google Threat Intelligence Group (GTIG) reports.

    Advertisement

    Also known as Krypton, Snake, Summit, UAC-0194, Venomous Bear, and Waterbug, Turla has been active since at least 2004. The US officially linked the APT to Russia’s Federal Security Service (FSB) in 2023.

    According to a fresh GTIG report, Turla has been developing a .NET backdoor tracked as StockStay since 2022, and has been using it in attacks against Ukraine’s government and military, as well as against entities with an interest in Italian foreign policy.

    Designed for ongoing cyber espionage, the backdoor shows code and functionality overlap with Kazuar, a known Turla implant that has been around since at least 2015.

    A multi-component backdoor written in .NET, StockStay initially masqueraded as a stock market data viewing tool, but recent iterations pose as PDF viewers and calculator utilities.

    The backdoor relies on a secure WebSocket connection, via the open source websocket-sharp library, for command-and-control (C&C) communication. Its components use an inter-process communication (IPC) channel to communicate with one another.

    Advertisement. Scroll to continue reading.

    StockStay payloads are fetched from a remote server using a proxy-aware downloader named StockStay.MarketMaker, which runs in the background and sets up autorun entries to execute core backdoor components.

    Network communication is provided through StockStay.StockBroker, a proxy-aware tunneler, while the implant’s configurability is enabled through the StockStay.StockMarket orchestrator. An encrypted on-disk configuration file contains various options regarding malware execution.

    The backdoor component, named StockStay.StockTrader, supports various command execution capabilities, including file download/exfiltration/modification, folder tampering, screen capture, task processing, registry modification, process execution, and system information harvesting.

    Most of the observed StockStay activity has been targeting Ukrainian government and military entities, in line with Russian interests in the region. In-country compromised infrastructure, including government services, has been used for malware deployment, GTIG says.

    Some of the early StockStay activity, however, targeted European entities in Italy, the Netherlands, Poland, and Germany, including a foreign affairs ministry, but the intended victims for most of these infections have not been confirmed.

    StockStay operations rely on academia and diplomacy themes: phishing emails sent from a compromised Ukrainian university email account and diplomatic education platform, filenames containing academic institution names, phishing domains containing ‘education’ and ‘diplo’ in their names, and backdoor MSI files named ‘DiplomacyEduAI’.

    GTIG also observed Turla deploying the backdoor via malicious RDP configuration files delivered via phishing emails. Some of these files were hosted on a compromised diplomatic-themed education platform.

    Additionally, GTIG noticed that the cyberespionage group deployed StockStay at different stages of its attacks, either for initial access, for reconnaissance, or at later stages, likely through existing access to the victim’s environment.

    In one attack in November 2025, Turla sent phishing emails to 20 Ukraine-based targets, linking to a malicious RAR archive exploiting CVE-2025-8088 for the execution of StockStay. In January, GTIG warned that multiple Russian APTs and cybercrime groups had been targeting the WinRAR vulnerability.

    Related: Russian Initial Access Broker Behind FortiBleed Campaign

    Related: Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say

    Related: Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks

    Related: UK Cyberspying Chief Calls AI ‘an Unstoppable Force’ and Warns About Russia

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    $3 Million Reportedly Stolen in Polymarket Hack

    June 27, 2026

    Chinese Framework Powers 200,000 Scam Sites

    June 27, 2026

    Nebulock Raises $25 Million for AI-Native Contextual Security

    June 27, 2026

    In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs

    June 27, 2026

    More Klue Breach Victims Identified as Hackers Get Hacked

    June 26, 2026

    Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories

    June 26, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026169 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 202690 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets

    June 28, 2026

    Tom Hanks Frets AI Could Voice Woody in Even More “Toy Story” Movies

    June 28, 2026

    Getting to Mars may require a pit stop in orbit, and NASA just tested the nozzle to make that happen

    June 28, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.