
Turla APT Deploys STOCKSTAY and Kazuar Backdoors in Global Espionage Campaign Against Diplomatic Entities
Russian-linked APT group Turla (Secret Blizzard) has intensified its espionage operations, utilizing the new STOCKSTAY malware alongside updated Kazuar backdoors to target government and diplomatic sectors.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- High
- Actor Type:
- Nation-State
- Geography:
- Europe and Central Asia
- Confidence:
- High Confidence
- Source:
- Google Threat Analysis Group (TAG)
- Read Time:
- 4 min
Executive Summary
Recent intelligence reports from late August 2026 indicate a significant escalation in cyber espionage activities attributed to the Russian-aligned threat actor Turla, also known as Secret Blizzard or Snake. The group, which is widely believed to operate under the Russian Federal Security Service (FSB), has been observed deploying a sophisticated dual-malware strategy. This campaign involves the use of a newly identified malware family dubbed STOCKSTAY, working in tandem with updated iterations of the long-standing Kazuar backdoor. The primary targets include diplomatic missions, government ministries, and international research organizations across Europe and Central Asia. The timing of these operations suggests a strategic push to gather intelligence on shifting geopolitical alliances.
Threat Analysis
Turla’s latest campaign demonstrates a refined approach to persistent access and data exfiltration. Unlike previous operations that relied heavily on broad spear-phishing, this current wave utilizes highly targeted lures tailored to the specific geopolitical interests of the Russian state. The threat actors are leveraging legitimate cloud services, such as Cloudflare Workers and GitHub, to host their command-and-control (C2) infrastructure, making detection significantly more difficult for traditional perimeter defenses. The campaign is characterized by its "low and slow" methodology, where the actors remain dormant for extended periods to avoid triggering behavioral alerts. This patience allows them to maintain access for months, systematically mapping internal networks before exfiltrating high-value data.
Technical Details
The STOCKSTAY malware is a modular backdoor written in C++ that serves as the initial stage of the intrusion. It is designed to perform system reconnaissance and establish a secure communication channel with the C2 server. Once a foothold is secured, the actors deploy the Kazuar backdoor. Kazuar is a highly complex .NET-based malware that has been in Turla's arsenal for years but has recently undergone a major overhaul. The 2026 version features enhanced encryption for its configuration files and a more robust set of commands for file manipulation, process injection, and credential harvesting. Notably, Kazuar now includes a "stealth mode" that monitors for the presence of specific forensic tools and sandboxes, terminating its execution if detected. It also utilizes a new DGA (Domain Generation Algorithm) that makes blocking its C2 traffic a moving target for defenders.
Attribution Assessment
Encrygma analysts, in alignment with reports from Google’s Threat Analysis Group (TAG) and Picus Security, assess with high confidence that this activity is the work of Turla. The attribution is based on the reuse of specific code snippets within the Kazuar backdoor that have been unique to Turla for over a decade. Furthermore, the C2 infrastructure overlaps with known FSB-linked IP ranges and domain registration patterns previously documented in Turla operations. The targeting of diplomatic entities in regions currently experiencing heightened geopolitical tension with Russia further supports this assessment, as the intelligence gathered directly serves the Kremlin's strategic objectives.
Implications
The deployment of STOCKSTAY and the revitalization of Kazuar signal a renewed investment by Russian intelligence in long-term espionage capabilities. The ability of these tools to bypass modern EDR (Endpoint Detection and Response) solutions through the use of legitimate cloud services poses a severe risk to sensitive government communications. If successful, these operations could lead to the compromise of classified diplomatic cables, strategic policy documents, and personal information of high-ranking officials. This level of access provides the Russian state with a significant advantage in international negotiations and regional security planning.
Recommendations
Organizations in the government and diplomatic sectors should immediately implement the following measures:
- Enhance monitoring of outbound traffic to legitimate cloud services like GitHub and Cloudflare for unusual patterns or unauthorized API calls.
- Deploy advanced memory scanning tools capable of detecting the Kazuar backdoor's injection techniques.
- Implement strict application whitelisting to prevent the execution of unauthorized binaries like STOCKSTAY.
- Conduct targeted threat hunting for indicators of compromise (IOCs) associated with recent Turla activity, specifically looking for the unique mutexes and registry keys used by the 2026 Kazuar variant.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
