thehackernews.com
TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
Cybersecurity researchers uncovered TASK#STOMP, a PowerShell backdoor that harvests business documents, Wi‑Fi passwords, clipboard data, and screenshots while accepting remote commands via two token‑authenticated C2 servers. Infection begins with a disguised VBScript (“95c9050t66.vbs”) executed through wscript.exe, establishing persistence through scheduled tasks and the Startup folder. The malware employs timestomping, hidden execution, and mutual‑watchdog modules to maintain a single active session and evade detection. It also opens a Chrome window to an Iranian tender database, though the purpose [...]