Interestana
Home/News/TASK#STOMP PowerShell Backdoor Steals Sensitive Data
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

TASK#STOMP PowerShell Backdoor Steals Sensitive Data

TASK#STOMP PowerShell Backdoor Steals Sensitive Data

Cybersecurity researchers have detailed a new malicious campaign identified as TASK#STOMP, which deploys a sophisticated PowerShell backdoor engineered to exfiltrate sensitive information from compromised computer systems. This backdoor operates with a broad mandate to automatically harvest and transmit various forms of data, including business documents, in real-time. A key function of the TASK#STOMP backdoor is its continuous monitoring of the filesystem. It is designed to watch for new files that appear in real time, indicating potential new data that could be of interest to the attackers. Once identified, these files are targeted for exfiltration. Beyond document theft, the backdoor possesses the capability to steal Wi-Fi passwords stored on the compromised host. This allows attackers to gain access to the network credentials, potentially enabling further lateral movement within the network or access to other connected devices. Furthermore, TASK#STOMP actively targets the contents of the user's clipboard. This means any information copied by the user, such as passwords, sensitive text, or financial details, can be captured and sent to the attackers. The backdoor also includes functionality for taking screenshots of the compromised system's display. This provides attackers with visual context of the user's activity, potentially revealing further sensitive information or confirming the presence of valuable data. In addition to data harvesting, the TASK#STOMP backdoor is designed to be remotely controllable. It can accept arbitrary commands from its operators, allowing them to direct its actions, request specific data, or deploy additional malicious payloads. This command-and-control capability makes the backdoor a versatile tool for ongoing espionage or further system compromise. The researchers have not yet publicly attributed the TASK#STOMP campaign to a specific threat actor or nation-state, but its capabilities suggest a well-resourced and determined adversary. The use of PowerShell for its backdoor component is a common tactic, as PowerShell is a legitimate administrative tool built into Windows operating systems, making it less likely to trigger immediate security alerts. The campaign highlights the persistent threat of sophisticated malware designed for data theft and network intrusion, underscoring the importance of robust endpoint security solutions and vigilant monitoring for unusual filesystem activity and network communications.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next