securityonline.info 24 Sept 2026, 07:11 UTC

PowerShell Backdoor TASK#STOMP Steals Documents and Wi-Fi Passwords

PowerShell Backdoor TASK#STOMP Steals Documents and Wi-Fi Passwords
CyberSIXT Evidence Panel Source marked as original reporting

SECURONIX researchers have detailed TASK#STOMP, a previously reported PowerShell backdoor targeting Windows endpoints and corporate document repositories. The malware’s initial access method remains unconfirmed; its observed delivery begins with a standalone VBScript on the victim’s desktop. The script creates a staging directory named WinDefendSvc, terminates earlier instances, launches a cleanup batch file and opens an Iranian tender webpage, possibly as a distraction. The Iranian content does not confirm the attackers’ nationality, and Securonix has not attributed the activity to a specific threat actor.

TASK#STOMP uses four scheduled tasks with rotating, Windows-like names, alongside a VBScript in the user’s Startup folder, to maintain access after reboots. It also backdates five files to 15 January 2024. Two hidden PowerShell branches compile embedded C# networking helpers at runtime and disable TLS certificate validation. One searches fixed drives for documents created or modified within the previous 365 days, watches for new or changed files and sends them over HTTP, compressing files larger than 10 MB.

The other polls two command servers, using a static token and failover, and can capture screenshots, clipboard contents and saved Wi-Fi passwords; unrecognised commands are executed through PowerShell.

Securonix recommends monitoring scheduled tasks created from user application paths, PowerShell Script Block Logging, dynamic C# compilation in user directories and unusual outbound requests with custom authentication headers. Because persistence is redundant, responders should remove all scheduled tasks and Startup entries rather than addressing only one component.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline