TASK#STOMP PowerShell backdoor with redundant C2
Malware Activity
Summary
Hide ▲
Show ▼
The TASK#STOMP PowerShell backdoor is stealing business documents, Wi‑Fi passwords, clipboard contents, and screenshots from compromised hosts while retaining remote command execution. It uses two redundant, token-authenticated C2 servers and multiple persistence layers to keep operating after one path is removed. The activity raises the risk of ongoing credential theft and long-lived access on infected Windows systems.
Related Happenings
TASK#STOMP PowerShell backdoor delivery campaign
Campaign
H score31
First: 21.09.2026 17:15
Last: 21.09.2026 17:15
Sources 1
How related:
Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts.
About this happening:
TASK#STOMP is a newly disclosed campaign that uses VBScript and PowerShell stages to deploy a backdoor on compromised hosts, creating ongoing risk of data thef...
TASK#STOMP PowerShell backdoor delivery campaign
CampaignHow related: Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts.
About this happening: TASK#STOMP is a newly disclosed campaign that uses VBScript and PowerShell stages to deploy a backdoor on compromised hosts, creating ongoing risk of data thef...
TerminalFix fake Cloudflare CAPTCHA reverse-tunnel campaign
Campaign
H score37
First: 30.08.2026 10:36
Last: 30.08.2026 10:36
Sources 1
About this happening:
The TerminalFix campaign is using fake Cloudflare CAPTCHA pages on compromised websites to trick users into running malicious PowerShell commands, expanding risk a...
TerminalFix fake Cloudflare CAPTCHA reverse-tunnel campaign
CampaignAbout this happening: The TerminalFix campaign is using fake Cloudflare CAPTCHA pages on compromised websites to trick users into running malicious PowerShell commands, expanding risk a...
ACR Stealer browser credential and document theft activity
Malware Activity
H score29
First: 17.07.2026 11:56
Last: 17.07.2026 11:56
Sources 1
About this happening:
ACR Stealer activity has expanded across enterprise environments, with Microsoft linking the malware to late April to mid-June 2026 campaigns that use ClickFix lur...
ACR Stealer browser credential and document theft activity
Malware ActivityAbout this happening: ACR Stealer activity has expanded across enterprise environments, with Microsoft linking the malware to late April to mid-June 2026 campaigns that use ClickFix lur...
Windows cryptocurrency clipper campaign targeting users via USB LNK worms
Campaign
H score32
First: 18.06.2026 17:30
Last: 18.06.2026 17:30
Sources 1
About this happening:
A Windows cryptocurrency clipper campaign is actively targeting users since February 2026, putting clipboard data, wallet addresses, and seed phrases at risk. The operatio...
Windows cryptocurrency clipper campaign targeting users via USB LNK worms
CampaignAbout this happening: A Windows cryptocurrency clipper campaign is actively targeting users since February 2026, putting clipboard data, wallet addresses, and seed phrases at risk. The operatio...
Malicious LNK GitHub C2 campaign targeting South Korea
Campaign
H score29
First: 02.04.2026 16:00
Last: 02.04.2026 16:00
Sources 1
About this happening:
A malicious LNK-file campaign targeting users in South Korea is using GitHub as C2 to support persistent access on Windows systems. The operation relies on Power...
Malicious LNK GitHub C2 campaign targeting South Korea
CampaignAbout this happening: A malicious LNK-file campaign targeting users in South Korea is using GitHub as C2 to support persistent access on Windows systems. The operation relies on Power...
Timeline
-
21.09.2026 17:15 2 articles · 2h ago
TASK#STOMP delivers a PowerShell backdoor that steals documents and credentials
Initial DisclosureSecuronix disclosed TASK#STOMP, a PowerShell backdoor campaign that begins when wscript.exe executes the encoded VBScript 95c9050t66.vbs from a victim's desktop, uses scheduled tasks and a Startup-folder launcher to persist as Local Credential Manager, Network Audio Service, Windows Display Manager, and Device Credential Handler, then runs hidden PowerShell modules such as sys_loader.ps1 and win_conn.ps1 to decode diag_pack.dat and win_conn_cfg.dat, maintain redundant token-authenticated C2 on corecloudfileshare[.]xyz and attachmentsharingdrive[.]xyz, and steal system metadata, business documents, Wi-Fi passwords, clipboard contents, screenshots, and arbitrary command execution; the chain also opens Chrome to irantenders[.]com and may run purge.bat to remove traces.
Show sources
- TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data — thehackernews.com — 21.09.2026 17:15
- TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data — thehackernews.com — 21.09.2026 17:15