general
Turla's StockStay Backdoor Hides Behind Academic Lures
2026-06-27

Russia's long-running espionage outfit Turla, also known as Snake, Venomous Bear and Waterbug, has spent the last three years quietly building a new .NET backdoor. Google's Threat Intelligence Group has now given it a name: StockStay. The targets are exactly who you'd expect. Ukrainian government and military bodies, plus a scattering of European organisations that work on Italian foreign policy.
A backdoor in many parts
StockStay isn't one tidy executable. It's a kit. The components carry stockbroker-themed names, MarketMaker, StockBroker, StockMarket, StockTrader, and between them they handle the full espionage routine: pulling down payloads, tunnelling traffic through proxies, orchestrating execution and doing the actual snooping. Screen captures, file theft, registry edits, process execution. The usual menu.
Early versions of the malware presented themselves as a stock market data viewer, which is where the naming convention comes from. Later builds dropped that costume for something more ordinary, posing as PDF readers and calculators. Command and control runs over secure WebSockets using the open source websocket-sharp library, which keeps the traffic looking unremarkable.
The lure is the story
The technical components are competent but not especially novel. What's worth lingering on is the social engineering wrapper Turla built around them.
The crew leaned heavily on academia and diplomacy. Phishing emails went out from a genuinely compromised Ukrainian university account and from a diplomatic education platform that had been hijacked for the purpose. Attachment filenames referenced real academic institutions. The phishing domains used words like education and diplo. One MSI installer was named DiplomacyEduAI, which is the sort of thing a busy policy researcher would double-click without much thought.
That's the point. The lures were calibrated for an audience that opens attachments from universities and foreign affairs contacts as a matter of routine. Anything else gets binned. Anything from a familiar academic sender gets opened.
Delivery methods
In a November 2025 wave, Turla sent emails to roughly 20 Ukrainian targets with links to a malicious RAR archive that exploited CVE-2025-8088, the WinRAR vulnerability that several Russian groups have been working hard to abuse throughout the year. The same operators have also delivered StockStay through booby-trapped RDP configuration files, occasionally hosted on the compromised diplomatic education site mentioned above.
- Compromised sender: a real Ukrainian university email account
- Themed lures: academic institutions, diplomatic training, AI policy
- Exploit of choice: CVE-2025-8088 in WinRAR
- Alternative delivery: malicious .rdp configuration files
A familiar pattern, still working
None of this is exotic. State-grade espionage still arrives via a believable email from a believable sender, written in the language of the recipient's day job. Turla's investment isn't in some exotic zero-click chain. It's in knowing exactly which academic conference a Ukrainian defence analyst would care about, and dressing the installer accordingly.
The technical artistry sits behind the lure, not in front of it. That's been true for years and it remains true here. Defenders who focus only on the payload end of the chain are looking at the less interesting half of the operation.