Signal
New backdoors STOCKSTAY and Mistic linked to espionage and ransomware access brokers
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-06-24 22:20 UTCUpdated 2026-06-25 14:00 UTC
rss
cveexploitsmalwarethreat_actorsincident_response
Trend in the last 24h
Current brief openSource links open
This current signal is open on the public brief with summary, metadata, source links, and full evidence. Pro adds compare-over-time, alerts, exports, and workflow.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.2 top sources shown
limited source diversity in top sources
Overview
Coverage centers on: Google Threat Intelligence Group on STOCKSTAY backdoor.
Entities
SymantecSTOCKSTAYMisticModeloRAT
Score total
0.96
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
- STOCKSTAY has been actively developed and deployed since December 2022 with recent analysis released in June 2026.
- Mistic has been observed in enterprise intrusions since April 2026, marking a recent escalation in ransomware-related access brokerage.
- Heightened geopolitical tensions and ransomware activity underscore the urgency of monitoring such backdoors.
Why it matters
- STOCKSTAY exemplifies ongoing state-sponsored cyber espionage targeting sensitive government and military sectors.
- Mistic illustrates how initial access brokers facilitate ransomware attacks by selling persistent network access.
- Understanding these backdoors aids in improving detection and defense strategies against espionage and ransomware threats.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
- STOCKSTAY is a .NET backdoor used by the Russia-linked Turla group for cyber espionage targeting government and military organizations.
- Mistic is a new backdoor linked to an initial access broker named Woodgnat, which sells network access to ransomware gangs.
How sources frame it
- Google Threat Intelligence Group: neutral
- Symantec Researchers: neutral
This briefing highlights two active backdoors linked to major cyber threat actors: Turla's espionage operations and ransomware access brokerage by Woodgnat.
All evidence
All evidence
Google Threat Intelligence Group on STOCKSTAY backdoor
cloud.google.com · cloud.google.com · 2026-06-25 14:00 UTC
CSO Online report on Mistic backdoor and ransomware broker Woodgnat
csoonline.com · csoonline.com · 2026-06-24 22:20 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
- cloud.google.com (1)
- csoonline.com (1)
Top origin domains (this list)
- cloud.google.com (1)
- csoonline.com (1)