Thehackernews TASK#STOMP: Advanced PowerShell Backdoor Stealing Sensitive Data
Article Content
- •TASK#STOMP is a PowerShell backdoor targeting Windows systems for document theft.
- •The malware uses multiple persistence methods, including scheduled tasks and Startup folder copies.
- •Current analysis does not attribute the malware to any known threat actor.
Securonix researchers have identified a sophisticated PowerShell backdoor named TASK#STOMP that targets Windows systems to steal sensitive business documents, Wi-Fi passwords, and clipboard data. The malware initiates via a VBScript file and establishes multiple persistence mechanisms, including scheduled tasks and a copy in the Startup folder. It employs rotating task names and timestamps to evade detection and complicate forensic analysis. The backdoor communicates with two redundant command-and-control servers, allowing attackers to execute arbitrary commands remotely. Although the exact number of affected organizations is unknown, the malware's design suggests a focus on corporate espionage rather than opportunistic crime. The campaign appears to have been active since at least January 2024, as indicated by the backdated timestamps in the malware. Researchers have not yet attributed the attack to a specific threat actor.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Red Heron Exploits Gitea RCE Flaw in Multinational Campaign A Chinese-speaking threat actor, tracked as Red Heron, exploited the CVE-2026-60004 remote code execution vulnerability in Gitea, compromising 1,386 instances across seven countries. The campaign involved source-code theft, credential collection, and lateral movement, affecting organizations in Canada, Argentina…