TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
Summary
Researchers have uncovered a new campaign called TASK#STOMP that utilizes a PowerShell backdoor to steal sensitive data from compromised systems. This backdoor is designed to harvest business documents, monitor file system changes, steal Wi-Fi passwords and clipboard data, and capture screenshots.
IFF Assessment
The TASK#STOMP backdoor represents a new threat that actively steals sensitive data from victims, posing a direct risk to defenders.
Defender Context
The TASK#STOMP backdoor highlights the ongoing threat of sophisticated PowerShell-based malware designed for data exfiltration. Defenders should be vigilant about detecting and preventing the execution of unauthorized PowerShell scripts and ensure robust endpoint detection and response (EDR) capabilities are in place to monitor for suspicious file system activity, clipboard access, and network exfiltration.