TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
thehackernews.com Sep 21, 2026

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

AI-summarised brief · reviewed before publication

Cybersecurity researchers uncovered TASK#STOMP, a PowerShell backdoor that harvests business documents, Wi‑Fi passwords, clipboard data, and screenshots while accepting remote commands via two token‑authenticated C2 servers. Infection begins with a disguised VBScript (“95c9050t66.vbs”) executed through wscript.exe, establishing persistence through scheduled tasks and the Startup folder. The malware employs timestomping, hidden execution, and mutual‑watchdog modules to maintain a single active session and evade detection. It also opens a Chrome window to an Iranian tender database, though the purpose remains unclear.

💡 Why It Matters

  • · The campaign showcases how attackers blend native Windows tools with sophisticated persistence and redundancy, making detection and removal far more difficult for defenders.