Find notable cyber news and cases, enriched with sources, timelines, and signals.

Turla STOCKSTAY phishing campaign targeting Ukraine and Europe

Campaign
First reported
Last updated
Happening score
H score 37
1 unique sources, 1 articles

Summary

Hide ▲

Turla's STOCKSTAY phishing campaign is targeting government and military organizations in Ukraine and selected European entities, extending a recurring espionage operation. The operation uses academic- or diplomatic-themed lures to deliver the malware and has been observed across early 2025 and November 2025. Later waves used RAR archives that exploited CVE-2025-8088 in WinRAR, showing the campaign's delivery methods evolved over time.

Related Happenings

Turla STOCKSTAY .NET backdoor deployment

Malware Activity
H score27 First: 26.06.2026 10:15 Last: 26.06.2026 10:15 Sources 1

How related: The Russian state-sponsored threat actor known as Turla has been attributed to a previously undocumented .NET backdoor called STOCKSTAY that has been deployed against government and military organizations in Ukraine, and entities that have an interest in Italian foreign policy.

About this happening: Turla's STOCKSTAY backdoor has been newly detailed as a .NET espionage implant used against government and military organizations in Ukraine and entities linked to I...

Gamaredon WinRAR malware chain using GammaPhish, GammaLoad, GammaWorm, and GammaSteel

Malware Activity
H score49 First: 02.06.2026 21:21 Last: 02.06.2026 21:21 Sources 1

About this happening: Gamaredon used WinRAR CVE-2025-8088 in January 2026 to launch GammaPhish, which retrieved GammaLoad VBScript downloaders and set up host fingerprinting and fol...

Latest development: 09.06.2026 15:26

Trend Micro attributes ongoing exploitation of WinRAR CVE-2025-8088 against Ukrainian organizations to Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-0226). The campaigns use crafted RAR archives with hidden ADS payloads, a decoy PDF, a Startup-folder LNK, and a PowerShell chain via cmd.exe to launch GIFTEDCROOK (result.dll), while Earth Dahu's HTA-to-VBScript chain delivers GammaPhish, GammaLoad, and GammaSteel. The exfiltration path also shifts from Telegram to dedicated C2 servers, and Earth Dahu's use of the flaw is assessed to have remained active through at least April 10, 2026.

Secret Blizzard Kazuar modular P2P botnet

Malware Activity
H score28 First: 16.05.2026 17:15 Last: 16.05.2026 17:15 Sources 1

About this happening: Kazuar is being used in a multi-stage campaign in Ukraine that ESET says likely involves Gamaredon providing access and Turla/Secret Blizzard delivering the ba...

CANFAIL phishing campaign impersonating Ukrainian energy organizations

Campaign
H score32 First: 13.02.2026 19:27 Last: 13.02.2026 19:27 Sources 1

About this happening: A previously undocumented threat actor is running a CANFAIL phishing campaign that impersonates Ukrainian energy organizations to gain unauthorized access to email acc...

Tomiris 2025 government-targeting campaign

Campaign
H score32 First: 01.12.2025 07:07 Last: 01.12.2025 07:07 Sources 1

About this happening: The Tomiris 2025 campaign is using phishing and public-service C2 to target foreign ministries, intergovernmental organizations, and government entities, i...

Timeline

  1. 26.06.2026 10:15 2 articles · 19d ago

    Turla STOCKSTAY phishing campaign targeting Ukraine and Europe

    Initial Disclosure

    In early 2025, Turla used a phishing email with a malicious RDP file attachment to establish contact with actor-controlled infrastructure before deploying additional payloads. The operation later broadened into a November 2025 wave using RAR archives that exploited CVE-2025-8088 in WinRAR.

    Show sources