Skip to content
TASK#STOMP: Advanced PowerShell Backdoor Stealing Sensitive Data

TASK#STOMP: Advanced PowerShell Backdoor Stealing Sensitive Data

First seen 21 Sep 2026, 15:22 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 21, 2026 at 16:21 UTC
  • TASK#STOMP is a PowerShell backdoor targeting Windows systems for document theft.
  • The malware uses multiple persistence methods, including scheduled tasks and Startup folder copies.
  • Current analysis does not attribute the malware to any known threat actor.

Securonix researchers have identified a sophisticated PowerShell backdoor named TASK#STOMP that targets Windows systems to steal sensitive business documents, Wi-Fi passwords, and clipboard data. The malware initiates via a VBScript file and establishes multiple persistence mechanisms, including scheduled tasks and a copy in the Startup folder. It employs rotating task names and timestamps to evade detection and complicate forensic analysis. The backdoor communicates with two redundant command-and-control servers, allowing attackers to execute arbitrary commands remotely. Although the exact number of affected organizations is unknown, the malware's design suggests a focus on corporate espionage rather than opportunistic crime. The campaign appears to have been active since at least January 2024, as indicated by the backdated timestamps in the malware. Researchers have not yet attributed the attack to a specific threat actor.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2024-01-15
Malware files backdated
TASK#STOMP backdates several files to January 15, 2024, as an anti-forensic technique.
Helpnetsecurity
2026-09-21
TASK#STOMP disclosed
Securonix researchers published details of TASK#STOMP, revealing its capabilities and operation methods.
Securonix
2026-09-21
Media coverage expands
Multiple cybersecurity outlets report on TASK#STOMP, confirming its espionage focus and operational methods.
Helpnetsecurity

More articles in this cluster (3)