TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

Summary

Researchers have uncovered a new campaign called TASK#STOMP that utilizes a PowerShell backdoor to steal sensitive data from compromised systems. This backdoor is designed to harvest business documents, monitor file system changes, steal Wi-Fi passwords and clipboard data, and capture screenshots.

IFF Assessment

FOE

The TASK#STOMP backdoor represents a new threat that actively steals sensitive data from victims, posing a direct risk to defenders.

Defender Context

The TASK#STOMP backdoor highlights the ongoing threat of sophisticated PowerShell-based malware designed for data exfiltration. Defenders should be vigilant about detecting and preventing the execution of unauthorized PowerShell scripts and ensure robust endpoint detection and response (EDR) capabilities are in place to monitor for suspicious file system activity, clipboard access, and network exfiltration.

Read Full Story →