Overview
- Securonix released a detailed analysis and indicators on Monday that include two C2 domains, file hashes and a static authentication token defenders can search for in network and proxy logs.
- The infection begins with an encoded VBScript run by wscript.exe from a file staged on the desktop that creates four scheduled tasks and a Startup copy to establish redundant persistence.
- Two hidden PowerShell modules run separately to steal files and maintain a second command channel and each module watches and restarts the other so the backdoor stays active if one process stops.
- TASK#STOMP automatically harvests business documents, saved Wi‑Fi passwords, clipboard content and screenshots while accepting remote commands, and it timestomps several files to a fabricated January 15, 2024 date to hinder forensic timelines.
- Securonix could not confirm the delivery vector or attribute the operator and recommends responders preserve artifacts, remove every persistence anchor in one coordinated action, block the listed domains and the static token, and monitor encrypted traffic for the token.