Turla's STOCKSTAY: A Fresh .NET Backdoor Aimed at Kyiv and Rome

Google's threat hunters tie the Russian FSB-linked crew to a previously undocumented Windows implant hitting Ukrainian military targets and Italy-focused diplomatic entities.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
Turla's STOCKSTAY: A Fresh .NET Backdoor Aimed at Kyiv and Rome
Share

Key points

  • Turla has deployed a previously undocumented .NET backdoor, STOCKSTAY, against Ukrainian government and military organizations.
  • Google Threat Intelligence Group describes the implant as continually developed, not a one-off deployment.
  • Italian foreign-policy entities are also in scope, extending Turla's reach into NATO diplomatic apparatus.
  • STOCKSTAY is a post-compromise tool with no associated CVEs; initial access vectors have not been publicly detailed.
  • Behavioral hunting on .NET loaders and outbound TLS patterns will outlast any hash-based detection.

What is STOCKSTAY?

STOCKSTAY is a Windows backdoor written in .NET, attributed to Turla, the Russian state-sponsored group also tracked as Snake and Venomous Bear. Google Threat Intelligence Group calls it continually developed, which means defenders should expect variants before the current indicators age out. It drops as part of broader intrusion sets, not as an initial-access tool, consistent with how Turla operates: get in first, then establish long-haul collection with bespoke malware.

Turla's tradecraft typically involves spearphishing or hijacked infrastructure for initial access, followed by custom implants. The group has also been caught reusing other actors' victims, piggybacking on Andromeda infections to reach targets they hadn't accessed directly.

Who is being targeted?

Ukrainian military and government victims fit Turla's established intelligence-collection remit. Our coverage of Russian cyber operations against Ukraine has tracked multiple actor groups in recent months: on 2 June 2026 we reported that Gamaredon was still exploiting a months-old WinRAR bug to reach Ukrainian endpoints, which shows how sustained and overlapping these campaigns are.

The Italian foreign-policy angle is the less-discussed half of this story. It's a clear signal that Turla's collection mandate runs well past the immediate war zone and into NATO member-state diplomatic circles. If you work for an Italian foreign-ministry contractor or advise on Ukraine policy from inside an EU institution, you are explicitly in scope.

Should you worry?

Depends on your exposure. For most organizations, this is a watch item. For CERT-EU constituents, Italian MFA contractors, or anyone supporting Ukrainian government functions, it warrants active hunting now.

Hunt for unusual .NET assemblies executing from user-writable paths. Turla has a long history of abusing legitimate cloud services for command-and-control, so permissive egress policies won't catch this. Watch PowerShell and WMI activity on hosts belonging to staff with diplomatic or Ukraine-policy portfolios.

The honest assessment: by the time STOCKSTAY hashes circulate widely, the next variant is probably already deployed. Indicator-based detection is necessary but not sufficient. Behavioral hunting on .NET loaders, scheduled-task persistence, and anomalous outbound TLS to legitimate SaaS endpoints is where the durable value is. Pull the Google writeup for IoCs and YARA rules, push the hashes to your EDR, and check telemetry going back at least 12 months. Turla plays a long game and it has been at this longer than most defenders have been watching it.

© 2026 Threat Vectr