The record
Written from the 1 report below. Nothing here is unsourced.
- The TASK#STOMP campaign deploys a multi-stage PowerShell backdoor to steal business documents, credentials, and monitor system activity.
- The malware uses disguised scheduled tasks and Windows startup scripts to maintain persistence on infected systems.
- It utilizes a mutual-watchdog mechanism between two distinct processes to ensure the backdoor remains active.
- The operation leverages native Windows components to blend in with legitimate system activity and avoid detection.
What to watch next
- Discovery of the initial access vector used to deliver the VBScript payload.
- Investigation into the purpose of the final-stage redirection to the irantenders.com website.
- Analysis of the unrecovered purge.bat script to determine its full impact on evidence cleanup.
Who said what4
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Securonix
2 quotes · 1 outlet
“Running the modules as separate processes provides functional separation and operational redundancy: failure or termination of one branch does not immediately remove the other”
In the article
…files, take screenshots, and execute arbitrary PowerShell commands - win_conn.ps1, which decodes "win_conn_cfg.dat" and sets up a secondary, persistent C2 channel with command execution and collection capabilities " Running the modules as separate processes provides functional separation and operational redundancy: failure or termination of one branch does not immediately remove the other ," Securonix said. Both the modules communicate with the same C2 infrastructure ("corecloudfileshare[.]xyz" or "attachmentsharingdrive[.]xyz"). Interestingly, the two components incorporate a mutual-watchdog…
“TASK#STOMP demonstrates this approach through a VBS-controlled framework that installs multiple persistence anchors and delegates follow-on functionality to PowerShell and dynamically compiled C# code. By relying almost entirely on native Windows components, the operation reduces its dependence on conventional executable payloads and makes individual events more difficult to distinguish from benign system activity.”
In the article
…not been recovered. "Threat actors routinely abuse Windows Script Host, PowerShell, Task Scheduler, and the .NET toolchain to blend malicious execution with legitimate administrative activity," the researchers said. " TASK#STOMP demonstrates this approach through a VBS-controlled framework that installs multiple persistence anchors and delegates follow-on functionality to PowerShell and dynamically compiled C# code. By relying almost entirely on native Windows components, the operation reduces its dependence on conventional executable payloads and makes individual events more difficult to distinguish from benign system activity. "…
Akshay Gaikwad
1 quote · 1 outlet
“automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary remote commands through two redundant, token-authenticated C2 servers”
In the article
…Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts. The backdoor " automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary remote commands through two redundant, token-authenticated C2 servers ," Securonix researchers Akshay Gaikwad and Aaron Beardslee said in a report shared with The Hacker News. The starting point of the infection chain is the use of "wscript.exe" to execute an encoded Visual Basic Script…
Aaron Beardslee
1 quote · 1 outlet
“automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary remote commands through two redundant, token-authenticated C2 servers”
In the article
…Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts. The backdoor " automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary remote commands through two redundant, token-authenticated C2 servers ," Securonix researchers Akshay Gaikwad and Aaron Beardslee said in a report shared with The Hacker News. The starting point of the infection chain is the use of "wscript.exe" to execute an encoded Visual Basic Script…
Coverage1
All filed from India
Named Iran · Google Chrome · Windows · Aaron Beardslee · Akshay Gaikwad · Securonix · TASK#STOMP
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
