Researchers have discovered TASK#STOMP, a PowerShell-based backdoor that targets business documents, Wi-Fi passwords, and clipboard data This article explores malware employs command. . The malware employs two command-and-control (C2) servers with automatic failover, ensuring operators can maintain access even if one server becomes unavailable.

TASK#STOMP employs dual Command & Control (C2) strategies, concealing its tasks with names that mimic legitimate Windows utilities such as "Local Credential Manager," "Network Audio Service," and "Windows Display Manager." This obfuscation makes it challenging to detect using name-based detection methods. The malware also hides its tracks by altering the timestamps of its files, including the VBS launcher, PowerShell scripts, encoded payload files, and configuration data, which are all assigned the same historical modification time of January 15, 2024.

The malware employs a static X-Auth-Token header and transitions to an alternate server when requests fail, enhancing reliability and making simple infrastructure removals less effective. Beyond document theft, TASK#STOMP can collect saved Wi-Fi passwords by executing netsh commands, stealing and clearing clipboard contents, gathering system information, and taking screenshots of the primary display. The malware compiles small C# helpers at runtime using the legitimate .NET compiler, csc.exe, which disables TLS certificate validation, allowing the implant to connect even when its C2 server uses an invalid, self-signed, or mismatched certificate.

Join 16,000+ SOC teams using ANY.RUN to enhance threat investigations and minimize manual workload.