Google analyzed the .NET backdoor STOCKSTAY, a multi-component implant used by Turla for espionage against government targets. It uses WM_COPYDATA IPC between components and a proxy-aware WebSocket tunneler to isolate network traffic from other malicious activity.
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
Detection can focus on inter-process communication via WM_COPYDATA messages and the use of websocket-sharp for C2 tunneling.
Read the original at Google Cloud — Threat Intelligence →
Subscribe
Short, high-signal articles and news summarized — at a frequency of your choosing. One click to subscribe.