TASK#STOMP PowerShell Implant Uses Dual C2 Servers for Document Theft and Remote Commands
Brief
Researchers have uncovered TASK#STOMP, a PowerShell-based backdoor that steals business documents, collects Wi-Fi passwords and clipboard data, captures screenshots, and executes attacker commands.
The malware uses two command-and-control (C2) servers with automatic failover, helping operators retain access if one server becomes unavailable.
The attack begins with a malicious Visual Basic Script (VBS) file launched through Windows Script Host. The script creates four scheduled tasks using XML files stored in the user’s LocalAppData directory.
It also places a copy of itself, named msdiag.vbs , in the Windows Startup folder to regain execution whenever the victim signs in.
