BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

TASK#STOMP Campaign Uses PowerShell Backdoor to Steal Data

TASK#STOMP campaign deploys PowerShell backdoor stealing documents, Wi-Fi passwords, and screenshots.

  • Security researchers have uncovered a new campaign dubbed TASK#STOMP that deploys a PowerShell backdoor on compromised systems.
  • The malware steals business documents, Wi-Fi passwords, and clipboard contents while taking screenshots and accepting remote commands via two redundant C2 servers.
  • The attack chain relies on VBScript, scheduled tasks, and the Windows Startup folder for persistence, using native system tools to evade detection.

Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts, as reported on September 21, 2026. The backdoor “automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary remote commands through two redundant, token-authenticated C2 servers,” according to Securonix researchers.

- Advertisement -

The starting point of the infection chain is the use of “wscript.exe” to execute an encoded Visual Basic Script (VBScript) file staged on the victim’s desktop (“95c9050t66.vbs”). The exact initial access pathway used to deliver the payload is unclear, although it’s possible that it may have been via email-based phishing or social engineering. By giving it a completely random file name, it’s suspected that the intention may have been to evade file name-based detection mechanisms.

The VBScript functions as the orchestrator for establishing persistence on the host using scheduled tasks and launching subsequent stages. The tasks are given the names Local Credential Manager, Network Audio Service, Windows Display Manager, and Device Credential Handler so as to blend in with regular operating system activity and avoid raising any red flags.

Meanwhile, the VBScript installer also sets up a backup persistence method that uses the Windows Startup folder to launch another script payload (“msdiag.vbs”) every time the user logs in. Consequently, the malware executes PowerShell commands to forcibly terminate previously running instances and ensure there exists only one active session. These strategies, paired with deliberate timestamp modification (aka timestomping), hidden execution, and cleanup behavior, suggest a deliberate effort to get around superficial administrative reviews and complicate forensic analysis. The use of redundant persistence methods guarantees continued execution even if one of them fails or is detected and removed.

The next phase involves running a pair of hidden PowerShell commands: sys_loader.ps1 decodes “diag_pack.dat” and initiates the document-stealing, surveillance, and remote-access payload, while win_conn.ps1 decodes “win_conn_cfg.dat” and sets up a secondary, persistent C2 channel. “Running the modules as separate processes provides functional separation and operational redundancy: failure or termination of one branch does not immediately remove the other,” Securonix said.

- Advertisement -

Both modules communicate with the same C2 infrastructure (“corecloudfileshare[.]xyz” or “attachmentsharingdrive[.]xyz”). Interestingly, the two components incorporate a mutual-watchdog relationship in which “diag_pack.dat” checks if “win_conn.ps1” is running, and restart it if not, and vice versa. In the final stage, the VBScript orchestrator opens Google Chrome in a maximized window and opens a specific URL from “irantenders[.]com,” which hosts a searchable database of all tenders and contracts issued by government departments and local authorities in Iran; the purpose behind this user-facing web action is unknown. Also launched is a batch script (“purge.bat”) that invokes a two-second delay and likely performs a clean-up to erase traces of the malicious activity. “Threat actors routinely abuse Windows Script Host, PowerShell, Task Scheduler, and the .NET toolchain to blend malicious execution with legitimate administrative activity,” the researchers said.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitmine 98% to 5% ETH goal after $74M buy

Bitmine bought 27,562 ETH, bringing its total holdings to 5,983,940 ETH ($16.1 billion), or...

Einride, Nvidia Partner for Next-Gen Autonomous Trucks

Einride will build its next-gen autonomous system on NVIDIA’s Drive Hyperion platform.The company expects...

Justin Sun’s $66M Math Prize Lacks Proof of Funds

Justin Sun announced the Justin Sun Prize, offering $1 million for solving 66 mathematical...

ECB launches Pontes to settle tokenized assets without stablecoins

The European Central Bank launched Pontes, a system for settling tokenized asset transactions in...

New ChainScript RAT uses blockchain-based C2 via ClickFix lures

Threat actors are deploying a new remote access trojan called ChainScript via ClickFix lures,...

Must Read

Top 10 Best Blockchain Games

If you want to know about the best blockchain games then read this article carefully. We listed the best games you can play and...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading