Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets

https://www.securityweek.com/wp-content/uploads/2024/09/Russian-GRU_Hackers.jpg

Russia-linked APT Turla has been targeting government and military organizations in Ukraine with a new backdoor specifically designed for espionage, Google Threat Intelligence Group (GTIG) reports.

Also known as Krypton, Snake, Summit, UAC-0194, Venomous Bear, and Waterbug, Turla has been active since at least 2004. The US officially linked the APT to Russia’s Federal Security Service (FSB) in 2023.

According to a fresh GTIG report, Turla has been developing a .NET backdoor tracked as StockStay since 2022, and has been using it in attacks against Ukraine’s government and military, as well as against entities with an interest in Italian foreign policy.

Designed for ongoing cyber espionage, the backdoor shows code and functionality overlap with Kazuar, a known Turla implant that has been around since at least 2015.

A multi-component backdoor written in .NET, StockStay initially masqueraded as a stock market data viewing tool, but recent iterations pose as PDF...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more