TASK#STOMP Windows Backdoor Exploit: Ongoing Document Theft Threat

www.news4hackers.com-task-stomp-windows-backdoor-exploit-ongoing-document-theft-threat-task-stomp-windows-backdoor-exploit-ongoing-document-theft-threat

Securonix researchers have uncovered a novel Windows backdoor campaign designated as TASK#STOMP, which employs sophisticated methods to exfiltrate sensitive business data while maintaining persistent access to compromised systems.

How TASK#STOMP Operates

The malware leverages Windows Script Host, PowerShell, and Task Scheduler to establish multiple execution pathways, ensuring resilience against removal attempts. The initial infection vector involves a VBScript installer that creates a directory named WinDefendSvc within the user’s LocalAppData folder. This folder mimics a legitimate Windows service to evade suspicion.

Infection Vector

The script then configures four scheduled tasks with system-like identifiers and places a secondary script in the Windows Startup folder. This multi-layered persistence mechanism ensures the malware remains active across reboots, even if individual components are deleted.

Obfuscation Techniques

To further obfuscate its presence, TASK#STOMP employs timestomping techniques. It terminates existing instances of its loaders and modifies the modification timestamps of five files to January 15, 2024. This manipulation disrupts timeline-based forensic analysis by making the files appear significantly older than their actual creation dates.

Malware Capabilities

The malware executes two hidden PowerShell scripts, sys_loader.ps1 and win_conn.ps1, which decode Base64-encoded payloads stored in diag_pack.dat and win_conn_cfg.dat. These payloads are executed in memory to avoid detection. The primary payload, diag_pack.dat, scans fixed drives for documents and archives, including Word files, PDFs, spreadsheets, presentations, and compressed files.

Data Exfiltration and Monitoring

It uploads identified files to attacker-controlled infrastructure and continuously monitors for new or modified documents. Additional capabilities include stealing saved Wi-Fi credentials, capturing screenshots, extracting clipboard data, and executing arbitrary PowerShell commands.

Persistence Mechanisms

A secondary payload establishes an alternative command-and-control (C2) channel with overlapping functionalities. Both PowerShell components monitor each other, automatically restarting if terminated, thereby reinforcing the malware’s persistence.

Technical Details and C2 Infrastructure

Securonix has not linked TASK#STOMP to a specific threat actor or determined the initial compromise vector. The affected organization’s details and industry remain undisclosed. The malware’s reliance on legitimate Windows components, such as PowerShell, reduces its detectability.

C2 Domains and Communication

Two C2 domains have been identified: corecloudfileshare.xyz and attachmentsharingdrive.xyz. The installer also triggers a web request to irantenders.com, though its purpose remains unclear.

Recommendations and Indicators of Compromise

The malware also dynamically compiles a small C# helper at runtime to bypass TLS certificate validation, enabling communication with C2 servers even when certificates are invalid, self-signed, or mismatched. Securonix advises organizations to monitor for anomalous VBScript or PowerShell activity originating from user-writable directories, the creation of unexpected scheduled tasks, and PowerShell processes invoking the .NET C# compiler.

Indicators of Compromise

Indicators of compromise include PowerShell Script Block Logging, AMSI telemetry, and scheduled-task activity logs. The campaign highlights the evolving tactics of adversaries targeting enterprise environments, emphasizing the need for proactive monitoring of behavioral anomalies rather than relying solely on signature-based detection.

According to Securonix researchers, TASK#STOMP represents a significant evolution in malware tactics, leveraging legitimate system tools to maintain persistence and evade detection.

Securonix advises organizations to prioritize monitoring for anomalous PowerShell and VBScript activity, as well as unexpected scheduled tasks, to detect and mitigate such threats.

  • C2 Domains: corecloudfileshare.xyz, attachmentsharingdrive.xyz
  • Additional Domain: irantenders.com (purpose unclear)



About Author

en_USEnglish