STOCKSTAY is a .NET-based multi-component Windows backdoor attributed to the Russia-linked espionage group Turla and used since at least December 2022 in intelligence collection operations. It has been deployed primarily against Ukrainian government, military, and defense-related organizations, and has also been observed targeting European entities, including organizations connected to Italian foreign policy and diplomatic interests. The malware is associated with long-term surveillance and post-compromise access in campaigns aligned with Russian state intelligence objectives.
STOCKSTAY uses a modular architecture built on .NET and Windows Forms. Reported components include a downloader, an orchestrator, a communications module, and a task-execution module. Command-and-control traffic is carried over secure WebSocket connections, while local component coordination uses inter-process communication based on WM_COPYDATA. The malware supports host reconnaissance, directory and file enumeration, file collection and exfiltration, screen capture, command and process execution, registry modification, and archive handling. Some variants generate host-specific identifiers and cryptographic material during execution, and the framework has been observed using execution scheduling and environmental constraints to reduce visibility and blend into normal user activity.
Turla has disguised STOCKSTAY as benign software to evade suspicion. Early variants masqueraded as stock market utilities, while later versions posed as PDF viewers and calculator applications. Delivery has been tied to phishing operations using academic, diplomatic, and military-themed lures, including malicious Remote Desktop Protocol files, MSI installers, HTA-based chains, and malicious RAR archives exploiting CVE-2025-8088. In multiple operations, Turla used compromised local infrastructure in Ukraine and third-party hosting services to stage payloads and obscure backend infrastructure.
STOCKSTAY shows significant architectural and code overlap with Turla's KAZUAR malware ecosystem, including shared obfuscation patterns, suggesting parallel development or maintenance by a common development team. It has been observed both as an initial access-enabling payload chain and as a later-stage persistence or fallback capability during active espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
That campaign used malicious RAR archives exploiting a WinRAR path traversal flaw tracked as CVE-2025-8088. | Russia-linked threat group Turla has been quietly expanding its espionage arsenal with a new backdoor called STOCKSTAY, actively targeting government and military organizations in Ukraine since at least December 2022.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Turla deployed STOCKSTAY (a .NET-based multi-component backdoor) to conduct long-term surveillance of Ukrainian and European diplomatic organizations.
Turla (SUMMIT) delivering the STOCKSTAY malware suite using Ukrainian army themes.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Researchers said Turla repeatedly used academic and diplomatic themes to lure victims. In one campaign, the attackers sent phishing emails from a compromised account belonging to a Ukrainian university. In another, they abused a diplomatic education platform to distribute malicious emails and files.
Initial access relied on phishing with malicious Remote Desktop Protocol files. In early 2025, victims received emails posing as a defense training academy, and opening the RDP attachment connected them to actor-controlled infrastructure.
This backdoor component handles the actual execution of malicious tasks, supporting a wide range of filesystem, registry, and command execution operations on the infected host.
calculator.rar RAR archive containing HTA lure and STOCKSTAY components
That campaign used malicious RAR archives exploiting a WinRAR path traversal flaw tracked as CVE-2025-8088.
In April 2025, STOCKSTAY adopted a new string obfuscation method based on a pseudo-random algorithm called Squirrel3... GTIG tracks this as K1MORPHER.
An encrypted on-disk configuration file contains various options regarding malware execution.
The malware is built in .NET and communicates with operators through a secure WebSocket connection, making it difficult to detect within normal network traffic.
Network communication is provided through StockStay.StockBroker, a proxy-aware tunneler...
In Ukraine, Turla used compromised infrastructure, including government services and an IT company’s server, to stage and deliver the payload. This lets the group blend into local network traffic, making detection considerably harder.
69 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
.NET-based multi-component backdoor used for long-term surveillance.
A .NET espionage backdoor used by Turla that communicates over secure WebSocket connections and is delivered via phishing and compromised local infrastructure. It uses a multi-component architecture: STOCKMARKET orchestrates operations, STOCKBROKER handles network communications, and STOCKTRADER executes commands such as file collection, registry modification, and screen capture. A downloader component, STOCKSTAY.MARKETMAKER, retrieves the full suite.
Backdoor malware referenced in a headline about deployment against Ukrainian targets.
A multi-component .NET backdoor used for cyber espionage. It masquerades as benign utilities, uses secure WebSocket C2, supports modular components for downloading payloads, tunneling communications, orchestration, and command execution including file exfiltration, screen capture, registry modification, process execution, and system information harvesting.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.