Help Net Security·4 min read

Fi passwords, screenshots, and business files

M
Mirko Zorz
Fi passwords, screenshots, and business files
Dive DeeperCreate a free account to unlock

The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files Researchers have taken apart TASK#STOMP, a Windows backdoor that searches a victim’s drives for business documents, uploads them to attacker servers, and then stays put to grab each new or edited document. The same malware steals saved Wi-Fi passwords and clipboard text, takes screenshots, and runs whatever command its operators send.

Akshay Gaikwad and Aaron Beardslee of Securonix Threat Research built their analysis from one infected machine, so Securonix cannot say how many organizations are affected. The malware plants at least five footholds, four scheduled tasks and a copy of itself in the Startup folder, and researchers warn that removing only one may leave the others able to rebuild the infection.

TASK#STOMP process flow reconstructed from observed process telemetry (Source: Securonix)

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in