Google Details Turla’s New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks
Google Threat Intelligence Group (GTIG) has attributed a previously undocumented .NET backdoor named STOCKSTAY to the Russian state-sponsored threat actor Turla. The…
Google Threat Intelligence Group (GTIG) has attributed a previously undocumented .NET backdoor named STOCKSTAY to the Russian state-sponsored threat actor Turla. The…
A now-patched flaw in WinRAR (CVE-2025-8088) was weaponized by Gamaredon to place malicious HTA downloaders into the Windows Startup folder, enabling automatic…
Gamaredon is a Russian advanced persistent threat group that has been highly active against Ukrainian governmental and military institutions, using spear-phishing, custom…