TASK#STOMP Windows backdoor steals documents, Wi-Fi passwords and screenshots
Securonix analyzed TASK#STOMP, a Windows backdoor that scans victim drives for business documents, uploads them to attacker servers and keeps grabbing new or edited files. The malware also steals saved Wi-Fi passwords and clipboard text, takes screenshots and plants at least five footholds: four scheduled tasks and a copy in the Startup folder.
- Backdoor creates 4 scheduled tasks named like "Network Audio Service" plus a Startup copy
- Files hide in a WinDefendSvc folder mimicking a Windows Defender service
- Document theft order: Word, PDF, PowerPoint, Excel, then archives
- Removing one component leaves others able to rebuild the infection
Read next
Security