Securonix Uncovers Windows Backdoor That Enables Continuous Document Theft

Securonix Threat Research has released new research on TASK#STOMP, a Windows backdoor designed to maintain long-term access and continuously steal business documents. The malware targets files across every fixed drive, monitors for new or modified documents and gives attackers ongoing remote access to the infected system.

Key findings include:

  • TASK#STOMP combines scheduled tasks, a Startup-folder launcher and rotating Windows-style task names to maintain persistence and evade detection.
  • Two PowerShell modules provide redundant command-and-control channels and can steal documents, saved Wi-Fi passwords and clipboard contents, capture screenshots and execute remote commands.
  • Its full capabilities may be missed in endpoint telemetry, but the broader chain of script execution, task creation, timestomping and runtime compilation provides defenders with strong detection opportunities.

You can read the research here: https://www.securonix.com/blog/task-stomp-powershell-backdoor-document-theft-remote-access

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading