Threat Advisory

PowerShell Backdoor Steals Documents and Enables Remote Access

Threat: Malware
Threat Actor Name: Watchdog
Targeted Region: Global
Alias: Thief Libra
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Threat actors abuse Windows Script Host, PowerShell, Task Scheduler, and toolchain to blend malicious execution with legitimate administrative activity. TASK#STOMP demonstrates this approach through a VBS-controlled framework that installs multiple persistence anchors and delegates follow-on functionality to PowerShell and dynamically compiled C# code. By relying almost entirely on native Windows components, the operation reduces its dependence on conventional executable payloads and makes individual events more difficult to distinguish from benign system activity.

The chain is staged under a user-writable path whose name resembles a Windows Defender service, while its scheduled-task display names imitate operating-system components. This masquerading strategy is paired with deliberate timestamp modification, hidden execution, process replacement, and cleanup behavior, indicating a coordinated effort to frustrate casual inspection and forensic timeline reconstruction. Redundant scheduled tasks and a Startup-folder launcher further ensure that execution can resume if one persistence mechanism is removed or fails.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Threat actors abuse Windows Script Host, PowerShell, Task Scheduler, and toolchain to blend malicious execution with legitimate administrative activity. TASK#STOMP demonstrates this approach through a VBS-controlled framework that installs multiple persistence anchors and delegates follow-on functionality to PowerShell and dynamically compiled C# code. By relying almost entirely on native Windows components, the operation reduces its dependence on conventional executable payloads and makes individual events more difficult to distinguish from benign system activity.

The chain is staged under a user-writable path whose name resembles a Windows Defender service, while its scheduled-task display names imitate operating-system components. This masquerading strategy is paired with deliberate timestamp modification, hidden execution, process replacement, and cleanup behavior, indicating a coordinated effort to frustrate casual inspection and forensic timeline reconstruction. Redundant scheduled tasks and a Startup-folder launcher further ensure that execution can resume if one persistence mechanism is removed or fails.[emaillocker id="1283"]

TASK#STOMP provides continuous document collection, credential and clipboard theft, screenshot capture, redundant command-and-control communications, and arbitrary remote-command execution. Its significance therefore lies not in any single technique, but in the way familiar Windows utilities are combined into a resilient espionage-oriented backdoor whose full capabilities are not apparent from process telemetry alone.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Execution T1059.001 Command and Scripting Interpreter PowerShell
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defence Evasion T1027.002 Obfuscated Files or Information Software Packing
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

MBC MAPPING:

Objective Behavior ID Behavior
Persistence F0012 Registry Run Keys / Startup Folder
Execution B0023 Install Additional Program
Anti-Static Analysis E1027 Obfuscated Files or Information
Defense Evasion B0029 Polymorphic Code
Command & Control B0030 C2 Communication
Impact B0022 Remote Access
Discovery E1083 File and Directory Discovery
Exfiltration E1020 Automated Exfiltration
Defense Evasion F0004 Disable or Evade Security Tools

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu