TASK#STOMP: the Windows backdoor that steals business documents and Wi-Fi passwords
The TASK#STOMP malware, analyzed by Securonix Threat Research, represents a serious threat to corporate networks. This Windows backdoor steals business documents, saved Wi-Fi passwords, and text from the clipboard, takes screenshots, and maintains a persistent presence in the system to continue exfiltrating data.
Quick Response
TASK#STOMP is a Windows backdoor that steals business documents, Wi-Fi passwords, and text from the clipboard. It installs via a VBScript that creates four scheduled tasks and a copy of itself in the Startup folder. The malware prioritizes Word, PDF, PowerPoint, and Excel documents, indicating a business espionage objective. Currently, it is not attributable to a known APT.
Five Points of System Entry
The infection begins with a VBScript file placed on the user's desktop. This script creates four scheduled tasks with names that mimic Windows components, such as "Network Audio Service," and copies itself to the Startup folder to ensure automatic execution upon the next login. The malware files reside in a folder named WinDefendSvc, a name reminiscent of a Windows Defender service.
Removing the script from the desktop does not remove the copy in the Startup folder. Two hidden PowerShell modules manage the data theft: one searches for documents, the other maintains a connection with the attackers' servers. Both modules are designed to restart the partner if one of them stops, although Securonix has identified a bug that leaves part of this logic unused.
Specific Targets and Time Deception Technique
The malware opens a web page in Chrome with a domain themed IranTenders, suggesting a possible targeting of organizations involved in tenders, contracts, or trade/procurement related to Iran. However, Securonix warns that a single decoy domain is not sufficient to confirm specific sectoral or regional targeting.
The malware backdates some of its files to January 15, 2024, as an anti-forensic technique, an attempt to mislead temporal analyses. Securonix emphasizes that this date is artificial and does not indicate the real start of the campaign.
Infection Vector and Recommendations
Securonix has not been able to confirm the malware delivery vector but estimates it is likely a phishing email with a ZIP, ISO, or IMG attachment containing the VBS script. Recommendations include blocking or alerting when Windows Script Host executes files from folders like Desktop, Download, or Temp, restricting Windows Script Host for standard users, and blocking ISO, IMG, and VBS attachments at the email gateway.
Attacker Profile
The malware features a relatively sophisticated design, with two modules monitoring each other and the ability to automatically switch to a backup server. However, both modules contain nearly identical code to skip security certification checks and present the same bug, indicating that the code was copied and pasted rather than developed and tested separately.
This profile—capable tools built on a base of reused or templated code, without rigorous internal review—is more typical of a mid-level operator than a mature and disciplined APT. The static and hardcoded authentication token represents a durable and high-confidence network indicator that can help link future incidents to the same operation or infrastructure.
Incident Response
Securonix experts recommend saving copies of the malware files and scheduled task definitions for analysis before taking any action. Next, it is necessary to stop the running scripts, remove all scheduled tasks created by the malware, the copy in the Startup folder, and the files staged in a single coordinated operation, and block the two command servers. After rebooting, it is essential to verify that none of the malware scripts resume execution.
To delve deeper into identity-based threat intelligence techniques, a dedicated eBook is available: Identity-First Threat Intelligence.
Implications for Cyber Insurance and Compliance
The analysis of TASK#STOMP raises important considerations for companies evaluating a cyber risk policy. The malware's ability to persist in the system and steal sensitive documents underscores the importance of an MDR service (Managed Detection and Response) for early detection of similar threats. Affected companies may face significant breach remediation costs, making adequate coverage crucial.
Furthermore, the presence of this type of malware highlights the need for NIS2 adjustment and DORA compliance for organizations operating in critical sectors. The regulations require advanced security measures and robust incident response procedures, which could help mitigate the impacts of threats like TASK#STOMP.
Proactive Protection and Risk Management
For organizations seeking to strengthen their security posture, it is essential to implement a Security Information and Event Management (SIEM) to monitor and analyze security events in real-time. Additionally, a SOC as a Service can provide continuous monitoring and managed incident response by experts.
Protection against advanced threats like TASK#STOMP also requires a structured approach to identity management and a zero trust architecture. These measures can help limit unauthorized access and reduce the attack surface available to attackers.
Final Considerations
The discovery of TASK#STOMP underscores the need for a multi-layered approach to cybersecurity. Organizations must invest in advanced incident response and managed SOC solutions to effectively address emerging threats. Additionally, compliance with regulations such as NIS2 and DORA is essential to ensure operational resilience and protection of sensitive data.
Threat Market and Related Trends
The emergence of TASK#STOMP fits into a context of increasing sophistication of cyber threats directed against critical sectors. According to recent reports, attacks targeting organizations involved in public procurement and international procurement have increased by 37% in the first half of 2024, with a particular focus on infrastructures related to emerging markets like Iran. This trend underscores the importance of investing in cyber insurance solutions that specifically cover industrial espionage scenarios.
Operational Impact and Hidden Costs
Companies affected by TASK#STOMP may face significant operational costs, not only for breach remediation, but also for the loss of competitiveness resulting from the leakage of strategic documents. An analysis conducted by Ponemon Institute estimates that the average cost of an incident related to the theft of business documents is around €2.5 million, with peaks exceeding €5 million for organizations operating in highly regulated sectors such as finance.
Advanced Defense Strategies
To effectively counter threats like TASK#STOMP, organizations should consider implementing enterprise Data Loss Prevention (DLP) solutions, which can monitor and block the unauthorized transfer of sensitive documents. Additionally, the adoption of an advanced Security Information and Event Management (SIEM), integrated with machine learning techniques, can significantly improve the ability to detect anomalous behaviors associated with persistent malware.
Compliance and Audit Challenges
The presence of TASK#STOMP raises important issues related to NIS2 compliance and DORA compliance. Both regulations require organizations to implement advanced security measures and robust incident response procedures. A security audit conducted by a certified entity could reveal significant gaps in the security posture of many companies, especially those that have not yet adapted their systems to the new regulations.
Future Forecasts and Threat Evolution
Experts predict that in the coming months, we will see an increase in attacks exploiting time deception and system persistence techniques. The ability of TASK#STOMP to backdate its files suggests that attackers are becoming increasingly skilled at hiding traces of their activities. This trend could lead to an increase in the cost of cyber insurance, especially for organizations that do not adopt adequate security measures.
Necessary Investments for Cybersecurity
To effectively address emerging threats, organizations should consider investing in an MDR service (Managed Detection and Response), which can provide expert-managed incident response. Additionally, the adoption of a SOC as a Service can offer continuous monitoring and advanced protection against persistent threats like TASK#STOMP.
Final Considerations and Immediate Actions
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication nor an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all liability for the misuse of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.