Adversary Intelligence — 2026-06-26

Google Reveals FSB-Linked Turla Group Deploying StockStay Backdoor Against Ukrainian Government and Defense Targets

BLUFSTOCKSTAY's parallel deployment alongside KAZUAR confirms Turla has built redundant persistent access into Ukrainian government networks that discovery of either toolkit alone cannot remediate.

Google Threat Intelligence Group on June 26 attributed STOCKSTAY to Turla, publicly linked by CISA to Center 16 of Russia's FSB 12. The .NET backdoor has been in continuous development since at least December 2022, primarily targeting Ukrainian government and military organizations; early versions also targeted entities in Italy, the Netherlands, Poland, and Germany before operations shifted to the Ukrainian government and defense focus 12. GTIG identified significant code and functional overlaps with KAZUAR, a prior Turla toolkit, and found 2025 variants shifting from a stock-market application masquerade to impersonating PDF readers and calculators 1. Delivery used phishing emails with malicious RDP configuration files, with lures drawing on academic and diplomatic themes, including a compromised Ukrainian university email account and a hijacked diplomatic education platform 12.

Analysis
STOCKSTAY's two-stage architecture, hardcoded initial access then environment-keyed targeting, establishes that Turla completed host-level reconnaissance inside some target networks before deploying the implant. Delivery through a compromised Ukrainian university account and a hijacked diplomatic-education platform signals penetration of trusted institutional infrastructure beyond direct government targets. KAZUAR code lineage reflects deliberate parallel-toolkit construction; a confirmed KAZUAR infection does not establish STOCKSTAY clearance. The concurrent SBU-FBI disclosure of Russian social engineering against messaging accounts across Ukraine and Europe confirms dual-track tradecraft: bespoke implants for high-value targets alongside scalable credential harvesting. Based on Google's telemetry alone, the European early-stage samples may reflect public scanning-service uploads rather than deliberate regional targeting.
4 sources
  1. The Latest Addition to Turla's Intelligence Gathering Apparatus - Google Cloud Blog
  2. Turla group adds more malware to Russia's espionage efforts against Ukraine - The Record
  3. Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks - The Hacker News
  4. Ukraine and Eastern Europe defense industry targeted by novel Turla backdoor - Field Effect

View in full brief →

UNCLASSIFIED // OPEN SOURCE