STOCKSTAY Backdoor Campaign Uses Malicious RDP Files and WinRAR Exploit to Target Ukraine
A cyber-espionage campaign linked to Turla is using malicious Remote Desktop Protocol files and an older patched WinRAR flaw to deploy a .NET backdoor called STOCKSTAY against Ukrainian targets. The campaign was detailed by Google Threat Intelligence Group …