#commandAndControl
STOMP Backdoor Uses PowerShell for Sensitive Data Theft #ClipboardStealing #CommandAndControl #DataTheft
STOMP Backdoor Uses PowerShell for Sensitive Data Theft
An advanced malware campaign known as TASK#STOMP has recently been discovered, which utilizes a PowerShell-based backdoor to collect business documents, Wi-Fi passwords, clipboard data, and screenshots from compromised computers using a PowerShell backdoor. Moreover, the malware also provides attackers with remote command execution and maintains multiple channels for further access. VBScript files are executed via the legitimate Windows Script Host utility wscript.exe in order to initiate the infection.  In spite of the fact that the exact method of delivery has not been confirmed, phishing or social engineering could be considered possible methods of delivering the script. Following the script's delivery, it sets up a set of scheduled tasks resembling legitimate Windows components, establishing persistence.  By naming these tasks Local Credential Manager, Network Audio Service, Windows Display Manager, and Device Credential Handler, malicious activities can be blended seamlessly with normal system activities. Another persistence mechanism places another VBScript file in the Windows Startup folder, enabling it to run when the user logs in.  Upon launching the malware, it executes two PowerShell components. Among these are sys_loader.ps1, which collects documents, gathers system information, steals Wi-Fi passwords, monitors clipboards, captures screenshots, and executes remote commands. Another persistent command-and-control channel, win_conn.ps1, provides additional collection capability as well as a persistent command-and-control channel.  By monitoring each other and restarting the other process if one is disabled, this setup provides redundancy, making it more difficult to remove the malware if only one process is terminated or a single persistence entry is deleted. In addition to hiding execution activities, timestamp manipulations, and cleanup activities, Task#STOMP can also be used for continuous document theft, increasing the difficulty of detection and forensic investigation.  As opposed to collecting only files that are already present on an infected computer, TASK#STOMP monitors the file system for newly created or modified documents. This enables the collection of business files as they appear and change during an active infection. In addition to obtaining Wi-Fi credentials and clipboard contents, the malware targets saved Wi-Fi credentials as well.  With clipboard monitoring, operators can identify information temporarily copied by users, while screenshot capture allows them to view information displayed on a compromised system. By combining these capabilities with remote command execution, Task#STOMP is able to gather more information about user activity than a conventional file-stealing malware.  A separate command-and-control path, Win_conn.ps1, is maintained by TASK#STOMP in addition to data collection. From win_conn_cfg.dat, the component decodes its configuration and connects to attacker-controlled infrastructure at corecloudfileshare[.]xyz and attachmentsharingdrive[.]xyz. Researcher identification of related traffic can be improved by using a hardcoded authentication token for communication.  Parts of network communication are handled by a compiled C# component. During connection times, connections can proceed when certificates are invalid, self-signed, or otherwise mismatched due to the code disabling TLS certificate validation. This reduces the level of protection usually provided by certificate checks and makes it easier for the malware to communicate with its servers. Additionally, TASK#STOMP alters file timestamps and cleans up activity following execution to provide further anti-forensic measures.  According to the researchers, several files have been backdated to January 15, 2024, but that date is not conclusive of when the campaign began. This date was deliberately inserted by the malware, and therefore cannot be regarded as evidence of the age of the campaign. Securonix has not determined why the malware opens a page associated with irantenders[.]com in Chrome, but the page relates to government contracts and tenders in Iran.  Securonix has not established whether the site indicates a specific victim profile or why it is opened. Researchers have cautioned that the domain alone may not be sufficient to confirm the campaign's geographical or sectoral targeting. Securonix has not linked TASK#STOMP to a known threat group. Due to the use of a single compromised system, it is unclear how the overall campaign scope and duration were determined.  The initial delivery method is also unclear, although similar VBScript campaigns suggest phishing involving archive or disk image attachments as a possible route. To detect an infection, researchers recommend examining suspicious Windows Script Host and PowerShell activity that originates from writable locations, newly created scheduled tasks, and instances where PowerShell invokes the C# compiler from .NET C#.  A suspected infection can be investigated with additional evidence from PowerShell Script Block Logging, AMSI telemetry, and scheduled task records.
dlvr.it
September 22, 2026 at 3:01 PM
A question on #CommandAndControl tabled by Ben Obese-Jecty on 28-08-2026 has been answered by Luke Pollard. https://questions-statements.parliament.uk/written-questions/detail/2026-08-28/22833
September 7, 2026 at 9:20 PM
Σχεδόν ένα στα πέντε νέα domains μπορεί να είναι… παλιό.

Και κάποιοι εγκληματίες πληρώνουν εκατομ…

https://hacks.gr/plirosan-7-ekatommyria-gia-nekra-sites-to-skoteino-kolpo-ton-chakers-poy-xegela-akoma-kai-ta-antivirus/

#Cybersecurity #DropCatchDomains #SableSquirrel #QuasarRAT #CommandAndControl
August 16, 2026 at 5:38 AM
August 14, 2026 at 3:22 PM
📰 Critical VMware vCenter RCE Dieksploitasi untuk Membuka Akses Reverse SSH

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/08/14/kerentanan-vmware-vcenter-cve-2026-59310/

#adv
an#advancedPersistentThreat##aptd#broadcomc#c2a#commandAndControlr#cyberAttackr#cyberSecurityr#ehtag/cybersecurity" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#cybersecurity
August 14, 2026 at 8:41 AM
What wins a modern war — superior firepower, or the invisible network connecting every weapon, sensor and commander?**

Read the full Strategic Vanguard analysis:
(www.strategicvanguard.com/post/the-inv...)

Watch the full video:
(youtu.be/nukqeXuqqPU?...)

#StrategicVanguard #CommandAndControl
The Invisible Network: Why Modern Wars Are Won by Military Communications, Not Just Firepower
Firepower may destroy targets, but communication wins wars. From encrypted radios and military satellites to network-centric warfare and real-time battlefield awareness, modern armed forces rely on in...
www.strategicvanguard.com
August 8, 2026 at 6:36 AM
📰 Malware HollowGraph Pakai Microsoft Graph untuk Komunikasi C2 Terselubung

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/07/21/malware-hollowgraph-microsoft-graph-c2/

#com
ma#commandAndControlr#cybersecurityu#dnsTunnelingp#groupollo#hollowgrapha#keamananSibera#malwareo#mshtag/microsoft365" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#microsoft365
July 21, 2026 at 8:34 AM
😎SeroRAT Un framework de Comando y Control (C2) para ejercicios autorizados de *Red Team* e investigación de seguridad.

www.hackingteamoficcial.uk/posts/6a5a90...

#SeroRAT #SeroC2 #CommandAndControl #C2Framework #RedTeam #InvestigaciónDeSeguridad
July 18, 2026 at 3:44 AM
📰 Google Gemini CLI Disalahgunakan untuk Mengelola Botnet dan Membantu Serangan Siber

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/07/16/google-gemini-cli-disalahgunakan-kelola-botnet/

#ai
#a#aif#artificialIntelligencee#botneta#commandAndControlr#cyberSecurityn#geminiClil#googlea#malware
July 16, 2026 at 7:49 AM
June 26, 2026 at 2:47 PM
June 12, 2026 at 1:09 PM
May 21, 2026 at 1:32 PM
May 20, 2026 at 9:53 PM
May 12, 2026 at 8:22 PM
ORION26 met les états-majors sous pression: postes de commandement mobiles, drones et cyber en simulation de guerre haute intensité totale
www.defense.gouv.fr/operations/a...
#Space #Science #Innovation #DefenseTech #MilitaryOps #Orion26 #CommandAndControl
ORION 26 : La manœuvre des postes de commandement au cœur de la haute intensité
Depuis le 7 avril, ORION26 a entamé sa quatrième et ultime phase, marquant une étape majeure dans la préparation opérationnelle des forces françaises. Cette séquence, dédiée à la projection et à la ré...
www.defense.gouv.fr
April 26, 2026 at 8:05 PM
📰 Gemini saidFBI Peringatkan Hacker Handala Gunakan Telegram Sebagai Pusat Kendali Malware

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/04/04/fbi-peringatkan-hacker-handala-gunakan-telegram-kendalikan-malware/

#ber
it#beritaTeknologia#commandAndControl##fbie#hackerHandalal#homelandJus
April 4, 2026 at 3:13 AM
March 24, 2026 at 4:30 AM
🕌 Iran’s Ayatollah Mojtaba Khamenei Reportedly Wounded and Evacuated to Russia as IRGC Seizes Control

READ MORE:
www.undergroundusa.com/i/191895427/...

LIKE, SHARE, FOLLOW, SUBSCRIBE

#News #Politics #Government #Iran #IRGC #Ayatollah #Russia #CommandAndControl @highlight @followers @everyone
March 23, 2026 at 10:35 PM
March 22, 2026 at 4:29 PM
March 11, 2026 at 2:08 PM
This was avoidable. How many more will die before Congress leaders stop Trump’s incompetent actions?

The US military has suffered losses in its fight with Iran. 3 American service members have been killed. #USmilitary #Iran #Commandandcontrol #Israel
share.newsbreak.com/hhw2pwlr
The US military has suffered losses in its fight with Iran. 3 American service members have been killed. - NewsBreak
President Donald Trump on Saturday warned that the US could suffer losses against Iran but called the operation "a noble mission."
share.newsbreak.com
March 1, 2026 at 7:48 PM