Securonix details TASK#STOMP Windows backdoor using tasks and VBS
Securonix published an analysis of TASK#STOMP, a Windows backdoor that relies only on components already present on the host. Persistence comes from four scheduled tasks defined by XML files in AppData plus a copy of msdiag.vbs in the Startup folder, while collection targets documents, clipboard, screenshots and saved Wi-Fi passwords.
- Four scheduled tasks from task.xml–task4.xml in AppData and msdiag.vbs in Startup
- Harvests Word, PDF, PowerPoint, Excel and archives, skipping files over 500 MB
- Uses netsh wlan to recover stored Wi-Fi profiles and plaintext passwords
- Two C2 domains: corecloudfileshare[.]xyz and attachmentsharingdrive[.]xyz
Read next
Security