Google: Turla has used the STOCKSTAY backdoor for espionage since 2022

Google Threat Intelligence reports that the Russia-linked actor Turla has used the .NET backdoor STOCKSTAY since at least December 2022 for intelligence gathering against Ukrainian government and military organisations, as well as entities tied to Italian foreign policy. The malware uses WebSocket-based command and control and modular components for tunnelling, orchestration and host operations. It overlaps with Turla's KAZUAR toolkit, and both its disguises and its infrastructure tactics evolved through 2025.

What this means for your organisation

Norwegian organisations in defence, foreign policy, research and critical infrastructure sit within the interest area of actors of this type. The goal is not a quick gain but long-lived, quiet access, and WebSocket command traffic blends into ordinary network activity. That makes detection dependent on logging and analysis over time rather than immediate alarms.

Berigo recommends

  • Retain endpoint and outbound traffic logs long enough to look months into the past.
  • Build detection for unusually long-lived outbound connections, including those to legitimate services.
  • Identify which parts of the organisation could be of intelligence interest and strengthen monitoring there.
  • Agree in advance on the route for reporting suspected state-linked activity to the national authorities.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch