Find notable cyber news and cases, enriched with sources, timelines, and signals.

Turla STOCKSTAY .NET backdoor deployment

Malware Activity
First reported
Last updated
Happening score
H score 27
1 unique sources, 1 articles

Summary

Hide ▲

Turla's STOCKSTAY backdoor has been newly detailed as a .NET espionage implant used against government and military organizations in Ukraine and entities linked to Italian foreign policy. The malware runs as a multi-component Windows Forms backdoor with secure WebSocket C2, letting operators route commands through separate downloader, tunneler, backdoor, and controller modules. Delivery has included phishing emails, malicious RDP files, MSI installers, and RAR archives; a November 2025 wave used CVE-2025-8088 in WinRAR. Suspected development traces back to December 2022, and the implant shares design overlaps with Kazuar.

Related Happenings

Turla STOCKSTAY phishing campaign targeting Ukraine and Europe

Campaign
H score37 First: 26.06.2026 10:15 Last: 26.06.2026 10:15 Sources 1

How related: Attacks distributing STOCKSTAY have consistently leveraged academic- or diplomatic-themed lures to target government and military organizations within Ukraine, with early versions of the backdoor used in attacks aimed at entities in Italy, the Netherlands, Poland, and Germany.

About this happening: Turla's STOCKSTAY phishing campaign is targeting government and military organizations in Ukraine and selected European entities, extending a recurring espionage opera...

Gamaredon WinRAR malware chain using GammaPhish, GammaLoad, GammaWorm, and GammaSteel

Malware Activity
H score49 First: 02.06.2026 21:21 Last: 02.06.2026 21:21 Sources 1

About this happening: Gamaredon used WinRAR CVE-2025-8088 in January 2026 to launch GammaPhish, which retrieved GammaLoad VBScript downloaders and set up host fingerprinting and fol...

Latest development: 09.06.2026 15:26

Trend Micro attributes ongoing exploitation of WinRAR CVE-2025-8088 against Ukrainian organizations to Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-0226). The campaigns use crafted RAR archives with hidden ADS payloads, a decoy PDF, a Startup-folder LNK, and a PowerShell chain via cmd.exe to launch GIFTEDCROOK (result.dll), while Earth Dahu's HTA-to-VBScript chain delivers GammaPhish, GammaLoad, and GammaSteel. The exfiltration path also shifts from Telegram to dedicated C2 servers, and Earth Dahu's use of the flaw is assessed to have remained active through at least April 10, 2026.

GammaWorm NTFS Alternate Data Streams propagation and backdoor activity

Malware Activity
H score40 First: 01.06.2026 14:00 Last: 01.06.2026 14:00 Sources 1

About this happening: The GammaWorm malware activity now shows a more covert stage that hides modules in NTFS Alternate Data Streams, helping it spread across Ukrainian networks while leavi...

Timeline

  1. 26.06.2026 10:15 2 articles · 19d ago

    Turla STOCKSTAY .NET backdoor deployment

    Initial Disclosure

    The earliest observed phase centered on a newly attributed Turla backdoor, STOCKSTAY, with suspected development activity reaching back to December 2022. Initial deployments targeted Ukraine and other European entities of interest, indicating an espionage-focused rollout.

    Show sources