{"id":3020,"date":"2026-09-21T16:32:24","date_gmt":"2026-09-21T16:32:24","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3020"},"modified":"2026-09-21T16:32:24","modified_gmt":"2026-09-21T16:32:24","slug":"taskstomp-powershell-backdoor-steals-documents-wi-fi-passwords-and-clipboard-data","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3020","title":{"rendered":"TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 21, 2026<\/span><\/span><span class=\"p-tags\">Endpoint Security \/ Malware<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhC3vJ8DX6852JxHepz1kGmunH3ZXsStcK4LINkLBCrzS8ZacBhqL-7epmGuzSNGI-jpF4GtkM-FXUsrv3croTLimjG_SBbw-rpO8NBIHf6Wvr6BMmYYSDKxEPQI-nrSFYrc9vmojcKn50LRFbc1t3h8qFA8dE_pZ3kMvelRpBFVFe2ZmCVJhPCWlMxYZpO\/s1700-nu-rw-lo-l85-e365\/stomp.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have disclosed details of a new campaign dubbed <strong>TASK#STOMP<\/strong> that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts.<\/p>\n<p>The backdoor \u00abautomatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary remote commands through two redundant, token-authenticated C2 servers,\u00bb Securonix researchers Akshay Gaikwad and Aaron Beardslee <a href=\"https:\/\/www.securonix.com\/blog\/task-stomp-powershell-backdoor-document-theft-remote-access\" target=\"_blank\">said<\/a> in a report shared with The Hacker News.<\/p>\n<p>The starting point of the infection chain is the use of \u00abwscript.exe\u00bb to execute an encoded Visual Basic Script (VBScript) file staged on the victim&#8217;s desktop (\u00ab95c9050t66.vbs\u00bb). The exact initial access pathway used to deliver the payload is unclear, although it&#8217;s possible that it may have been via email-based phishing or social engineering.<\/p>\n<p>By giving it a completely random file name, it&#8217;s suspected that the intention may have been to evade file name-based detection mechanisms. The VBScript functions as the orchestrator for establishing persistence on the host using scheduled tasks and launching subsequent stages.<\/p>\n<p>The tasks are given the names Local Credential Manager, Network Audio Service, Windows Display Manager, and Device Credential Handler so as to blend in with regular operating system activity and avoid raising any red flags.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The VBScript installer also sets up a backup persistence method that uses the Windows Startup folder to launch another script payload (\u00abmsdiag.vbs\u00bb) every time the user logs in to the system. In the next phase, the malware executes PowerShell commands to forcibly terminate previously running instances and ensure there exists only one active session <\/p>\n<p><a name=\"more\"\/><\/p>\n<p>These strategies, paired with deliberate timestamp modification (aka timestomping), hidden execution, and cleanup behavior, suggest a deliberate effort to get around superficial administrative reviews and complicate forensic analysis. The use of redundant persistence methods guarantees continued execution even if one of them fails or is detected and removed.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgM9hgW4fwVdFVj1eL4YUdUjv4Q0kboJTir3FjxPCBV2ftB5uzIiWCF9ne_OX-xG4HlGVLCXVOq-jVaCQobiEEM1VJ64UjJEV4kc4Y6AJEd4vVIma7aA0PaD3nhqOWfJ5BHUJNeSgLarLspcLEXnI7LfRadG6HTL59FZaUzxknewwq8KdsfLmJdmqwh8R1W\/s1700-nu-rw-lo-l85-e365\/flow.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgM9hgW4fwVdFVj1eL4YUdUjv4Q0kboJTir3FjxPCBV2ftB5uzIiWCF9ne_OX-xG4HlGVLCXVOq-jVaCQobiEEM1VJ64UjJEV4kc4Y6AJEd4vVIma7aA0PaD3nhqOWfJ5BHUJNeSgLarLspcLEXnI7LfRadG6HTL59FZaUzxknewwq8KdsfLmJdmqwh8R1W\/s1700-nu-rw-lo-l85-e365\/flow.png\" alt=\"\" border=\"0\" data-original-height=\"1850\" data-original-width=\"1800\"\/><\/a><\/div>\n<p>The next phase involves running a pair of hidden PowerShell commands &#8211;<\/p>\n<ul style=\"text-align: left;\">\n<li>sys_loader.ps1, which decodes \u00abdiag_pack.dat\u00bb and initiates the document-stealing, surveillance, and remote-access<\/li>\n<li>payload to steal system metadata, business documents, Wi-Fi passwords, and clipboard content, monitor for newly modified files, take screenshots, and execute arbitrary PowerShell commands<\/li>\n<li>win_conn.ps1, which decodes \u00abwin_conn_cfg.dat\u00bb and sets up a secondary, persistent C2 channel with command execution and collection capabilities<\/li>\n<\/ul>\n<p>\u00abRunning the modules as separate processes provides functional separation and operational redundancy: failure or termination of one branch does not immediately remove the other,\u00bb Securonix said.<\/p>\n<p>Both the modules communicate with the same C2 infrastructure (\u00abcorecloudfileshare[.]xyz\u00bb or \u00abattachmentsharingdrive[.]xyz\u00bb). Interestingly, the two components incorporate a mutual-watchdog relationship in which \u00abdiag_pack.dat\u00bb checks if \u00abwin_conn.ps1\u00bb is running, and restart it if not, and vice versa.<\/p>\n<p>The end goal of the attack is to provide a pathway for continuous document collection, credential and clipboard theft, screenshot capture, redundant C2 communications, and arbitrary code execution, while leveraging an array of techniques to fly under the radar.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-security-guide-b\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiXA4q3EC_2cN4xiJDYmo1tVcCX5KORpjgj8jSp3DntuUZH4f0zu1Ru8jUwzShrquIuOxPb6q9TxJJXGuj7rxDRsXRSD34thOrXdZ9tDITDEj3Ocp0Z6GwhGekRTMhMnFjJ8UA5iSkfSnmnZrFzY5cmUlbCNiTNDNVrZvyef-AR_RLqwITnqZNi6PjeZkPC\/s728-nu-rw-lo-l85-e365\/AI-eBook-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>In the final stage, the VBScript orchestrator opens Google Chrome in a maximized window and opens a specific URL from \u00abirantenders[.]com,\u00bb which hosts a searchable database of all tenders and contracts issued by government departments and local authorities in Iran. The purpose behind this user-facing web action is unknown.<\/p>\n<p>Also launched is a batch script (\u00abpurge.bat\u00bb) that invokes a two-second delay and likely performs a clean-up to erase traces of the malicious activity. That said, what this batch script does is unknown as its contents have not been recovered.<\/p>\n<p>\u00abThreat actors routinely abuse Windows Script Host, PowerShell, Task Scheduler, and the .NET toolchain to blend malicious execution with legitimate administrative activity,\u00bb the researchers said.<\/p>\n<p>\u00abTASK#STOMP demonstrates this approach through a VBS-controlled framework that installs multiple persistence anchors and delegates follow-on functionality to PowerShell and dynamically compiled C# code. By relying almost entirely on native Windows components, the operation reduces its dependence on conventional executable payloads and makes individual events more difficult to distinguish from benign system activity.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 21, 2026Endpoint Security \/ Malware Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3021,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[179,3479,38,2148,296,2505,295,3478,2842],"class_list":["post-3020","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-backdoor","tag-clipboard","tag-data","tag-documents","tag-passwords","tag-powershell","tag-steals","tag-taskstomp","tag-wifi"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3020","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3020"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3020\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3021"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3020"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3020"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3020"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}