Turla STOCKSTAY phishing campaign targeting Ukraine and Europe
Campaign
Summary
Hide ▲
Show ▼
Turla's STOCKSTAY phishing campaign is targeting government and military organizations in Ukraine and selected European entities, extending a recurring espionage operation. The operation uses academic- or diplomatic-themed lures to deliver the malware and has been observed across early 2025 and November 2025. Later waves used RAR archives that exploited CVE-2025-8088 in WinRAR, showing the campaign's delivery methods evolved over time.
Related Happenings
Turla STOCKSTAY .NET backdoor deployment
Malware Activity
H score27
First: 26.06.2026 10:15
Last: 26.06.2026 10:15
Sources 1
How related:
The Russian state-sponsored threat actor known as Turla has been attributed to a previously undocumented .NET backdoor called STOCKSTAY that has been deployed against government and military organizations in Ukraine, and entities that have an interest in Italian foreign policy.
About this happening:
Turla's STOCKSTAY backdoor has been newly detailed as a .NET espionage implant used against government and military organizations in Ukraine and entities linked to I...
Turla STOCKSTAY .NET backdoor deployment
Malware ActivityHow related: The Russian state-sponsored threat actor known as Turla has been attributed to a previously undocumented .NET backdoor called STOCKSTAY that has been deployed against government and military organizations in Ukraine, and entities that have an interest in Italian foreign policy.
About this happening: Turla's STOCKSTAY backdoor has been newly detailed as a .NET espionage implant used against government and military organizations in Ukraine and entities linked to I...
Gamaredon WinRAR malware chain using GammaPhish, GammaLoad, GammaWorm, and GammaSteel
Malware Activity
H score49
First: 02.06.2026 21:21
Last: 02.06.2026 21:21
Sources 1
About this happening:
Gamaredon used WinRAR CVE-2025-8088 in January 2026 to launch GammaPhish, which retrieved GammaLoad VBScript downloaders and set up host fingerprinting and fol...
Gamaredon WinRAR malware chain using GammaPhish, GammaLoad, GammaWorm, and GammaSteel
Malware ActivityAbout this happening: Gamaredon used WinRAR CVE-2025-8088 in January 2026 to launch GammaPhish, which retrieved GammaLoad VBScript downloaders and set up host fingerprinting and fol...
Latest development: 09.06.2026 15:26
Trend Micro attributes ongoing exploitation of WinRAR CVE-2025-8088 against Ukrainian organizations to Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-0226). The campaigns use crafted RAR archives with hidden ADS payloads, a decoy PDF, a Startup-folder LNK, and a PowerShell chain via cmd.exe to launch GIFTEDCROOK (result.dll), while Earth Dahu's HTA-to-VBScript chain delivers GammaPhish, GammaLoad, and GammaSteel. The exfiltration path also shifts from Telegram to dedicated C2 servers, and Earth Dahu's use of the flaw is assessed to have remained active through at least April 10, 2026.
Secret Blizzard Kazuar modular P2P botnet
Malware Activity
H score28
First: 16.05.2026 17:15
Last: 16.05.2026 17:15
Sources 1
About this happening:
Kazuar is being used in a multi-stage campaign in Ukraine that ESET says likely involves Gamaredon providing access and Turla/Secret Blizzard delivering the ba...
Secret Blizzard Kazuar modular P2P botnet
Malware ActivityAbout this happening: Kazuar is being used in a multi-stage campaign in Ukraine that ESET says likely involves Gamaredon providing access and Turla/Secret Blizzard delivering the ba...
CANFAIL phishing campaign impersonating Ukrainian energy organizations
Campaign
H score32
First: 13.02.2026 19:27
Last: 13.02.2026 19:27
Sources 1
About this happening:
A previously undocumented threat actor is running a CANFAIL phishing campaign that impersonates Ukrainian energy organizations to gain unauthorized access to email acc...
CANFAIL phishing campaign impersonating Ukrainian energy organizations
CampaignAbout this happening: A previously undocumented threat actor is running a CANFAIL phishing campaign that impersonates Ukrainian energy organizations to gain unauthorized access to email acc...
Tomiris 2025 government-targeting campaign
Campaign
H score32
First: 01.12.2025 07:07
Last: 01.12.2025 07:07
Sources 1
About this happening:
The Tomiris 2025 campaign is using phishing and public-service C2 to target foreign ministries, intergovernmental organizations, and government entities, i...
Tomiris 2025 government-targeting campaign
CampaignAbout this happening: The Tomiris 2025 campaign is using phishing and public-service C2 to target foreign ministries, intergovernmental organizations, and government entities, i...
Timeline
-
26.06.2026 10:15 2 articles · 19d ago
Turla STOCKSTAY phishing campaign targeting Ukraine and Europe
Initial DisclosureIn early 2025, Turla used a phishing email with a malicious RDP file attachment to establish contact with actor-controlled infrastructure before deploying additional payloads. The operation later broadened into a November 2025 wave using RAR archives that exploited CVE-2025-8088 in WinRAR.
Show sources
- Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks — thehackernews.com — 26.06.2026 10:15
- Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks — thehackernews.com — 26.06.2026 10:15