Turla APT STOCKSTAY and Kazuar Backdoor Analysis
Score: 8/10

Turla APT STOCKSTAY and Kazuar Backdoor Analysis

Turla (Secret Blizzard) targets government and military entities globally using the custom STOCKSTAY and Kazuar backdoors, often leveraging hijacked infrastructure.

Executive Summary

Turla, a Russia-aligned APT linked to the FSB, has maintained a high-tempo cyber-espionage operation since at least 2004. The group's primary focus is long-term intelligence collection against government, defense, and research organizations, with a recent heavy concentration on Ukrainian targets. Turla is known for its high level of operational stealth, frequently hijacking the C2 infrastructure of other threat actors, such as OilRig and Storm-0156, to mask its activities and expand its reach.

The group utilizes a sophisticated custom toolset, most notably the STOCKSTAY and Kazuar backdoors, which share a common obfuscation ecosystem (K1MORPHER). Their attack chain often includes specialized delivery mechanisms like malicious RDP configuration files and the exploitation of path-traversal vulnerabilities. Turla avoids traditional C2 attribution by routing traffic through legitimate serverless platforms and cloud services, while implementing environmental keying to ensure payloads only execute on intended victim machines.

Turla represents a persistent, high-tier threat capable of compromising supply chains and ISPs to conduct Adversary-in-the-Middle (AiTM) attacks. Their ability to adapt and integrate their tools with other actors' infrastructure makes them exceptionally difficult to track and attribute, requiring a defense-in-depth approach focused on behavioral detection and rigorous monitoring of cloud service abuse.

Key Details

Threat Name

Turla APT

Affects

WinRAR, Oracle PeopleSoft

Adversary

Turla Other Adversaries and Aliases: OilRig; Storm-0156; Gamaredon

Malware/Tools

STOCKSTAY, Kazuar, ApolloShadow, TinyTurla, LunarWeb, LunarMail, Chisel, Agent.BTZ, ComRAT, DIAMONDBACK

Report Score

8out of 10
Quality Score
Good
IOC Quality7
TTP Details9
Detection Guidance7
Enterprise Relevance9
Clarity & Structure8
Technical Depth9

Sources