Threat actors abuse Windows Script Host, PowerShell, Task Scheduler, and toolchain to blend malicious execution with legitimate administrative activity. TASK#STOMP demonstrates this approach through a VBS-controlled framework that installs multiple persistence anchors and delegates follow-on functionality to PowerShell and dynamically compiled C# code. By relying almost entirely on native Windows components, the operation reduces its dependence on conventional executable payloads and makes individual events more difficult to distinguish from benign system activity.
The chain is staged under a user-writable path whose name resembles a Windows Defender service, while its scheduled-task display names imitate operating-system components. This masquerading strategy is paired with deliberate timestamp modification, hidden execution, process replacement, and cleanup behavior, indicating a coordinated effort to frustrate casual inspection and forensic timeline reconstruction. Redundant scheduled tasks and a Startup-folder launcher further ensure that execution can resume if one persistence mechanism is removed or fails.[/subscribe_to_unlock_form]
Threat actors abuse Windows Script Host, PowerShell, Task Scheduler, and toolchain to blend malicious execution with legitimate administrative activity. TASK#STOMP demonstrates this approach through a VBS-controlled framework that installs multiple persistence anchors and delegates follow-on functionality to PowerShell and dynamically compiled C# code. By relying almost entirely on native Windows components, the operation reduces its dependence on conventional executable payloads and makes individual events more difficult to distinguish from benign system activity.
The chain is staged under a user-writable path whose name resembles a Windows Defender service, while its scheduled-task display names imitate operating-system components. This masquerading strategy is paired with deliberate timestamp modification, hidden execution, process replacement, and cleanup behavior, indicating a coordinated effort to frustrate casual inspection and forensic timeline reconstruction. Redundant scheduled tasks and a Startup-folder launcher further ensure that execution can resume if one persistence mechanism is removed or fails.[emaillocker id="1283"]
TASK#STOMP provides continuous document collection, credential and clipboard theft, screenshot capture, redundant command-and-control communications, and arbitrary remote-command execution. Its significance therefore lies not in any single technique, but in the way familiar Windows utilities are combined into a resilient espionage-oriented backdoor whose full capabilities are not apparent from process telemetry alone.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defence Evasion | T1027.002 | Obfuscated Files or Information | Software Packing |
| Credential access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Persistence | F0012 | Registry Run Keys / Startup Folder |
| Execution | B0023 | Install Additional Program |
| Anti-Static Analysis | E1027 | Obfuscated Files or Information |
| Defense Evasion | B0029 | Polymorphic Code |
| Command & Control | B0030 | C2 Communication |
| Impact | B0022 | Remote Access |
| Discovery | E1083 | File and Directory Discovery |
| Exfiltration | E1020 | Automated Exfiltration |
| Defense Evasion | F0004 | Disable or Evade Security Tools |
The following reports contain further technical details:
[/emaillocker]