Malware · 8h ago
Securonix says TASK#STOMP is a Windows PowerShell backdoor built to keep going even after a defender removes one piece. In the sample they tore down, it used a VBScript on the desktop to set four scheduled tasks and a Startup-folder copy, giving it at least five ways to launch again.
The malware splits theft and control across two hidden PowerShell modules: one hunts for business documents and watches for new files, while the other maintains the operator channel. It steals Wi‑Fi passwords, clipboard text, and screenshots, and can run remote commands; because the launch points are redundant, deleting one script or task can leave the infection alive.
For Windows workstations, the lasting risk is not just initial theft but a cleanup that looks finished while the backdoor still has a way back in. In environments that rely on single-IOC removal, TASK#STOMP is a reminder that persistence logic can outlast the obvious file you found first.
2 sources covering this story
TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
TASK#STOMP deploys a PowerShell backdoor that steals documents and Wi-Fi passwords, monitors files, and executes remote commands.
The TASK#STOMP backdoor steals office documents on Windows PCs, grabs new files as they're saved, and can rebuild itself if partly removed.
Part of the PlainSec briefing for 2026-09-21