Google Reveals FSB-Linked Turla Group Deploying StockStay Backdoor Against Ukrainian Government and Defense Targets
Google Threat Intelligence Group on June 26 attributed STOCKSTAY to Turla, publicly linked by CISA to
STOCKSTAY's two-stage architecture, hardcoded initial access then environment-keyed targeting, establishes that Turla completed host-level reconnaissance inside some target networks before deploying the implant. Delivery through a compromised Ukrainian university account and a hijacked diplomatic-education platform signals penetration of trusted institutional infrastructure beyond direct government targets. KAZUAR code lineage reflects deliberate parallel-toolkit construction; a confirmed KAZUAR infection does not establish STOCKSTAY clearance. The concurrent SBU-FBI disclosure of Russian social engineering against messaging accounts across Ukraine and Europe confirms dual-track tradecraft: bespoke implants for high-value targets alongside scalable credential harvesting. Based on Google's telemetry alone, the European early-stage samples may reflect public scanning-service uploads rather than deliberate regional targeting.
4 sources
- The Latest Addition to Turla's Intelligence Gathering Apparatus -
Google Cloud Blog - Turla group adds more malware to Russia's espionage efforts against Ukraine -
The Record - Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks -
The Hacker News - Ukraine and Eastern Europe defense industry targeted by novel Turla backdoor -
Field Effect