TASK#STOMP starts with a VBScript file on the desktop, then creates four scheduled tasks and a Startup folder copy for redundant persistence.
Two hidden PowerShell modules steal business documents, Wi-Fi passwords, and clipboard data while keeping a second command channel open.
Securonix found no link to any known APT group and assesses this as a mid-tier operator based on reused, buggy code.
The malware prioritizes Word, PDF, PowerPoint, and Excel files, pointing toward targeted document theft rather than opportunistic crime.
The delivery method and full campaign scope remain unconfirmed, since researchers only analyzed one infected device.
Securonix Threat Research has disclosed a new campaign called TASK#STOMP. It centers on a PowerShell backdoor built to harvest sensitive data from compromised Windows hosts.
Researchers Akshay Gaikwad and Aaron Beardslee built their analysis from a single infected machine. They cannot yet say how many organizations the campaign has affected.
The backdoor searches drives for business documents, uploads them to attacker servers, and keeps watching for new files. It also steals Wi-Fi passwords, clipboard content, and screenshots, and runs remote commands on demand.
How TASK#STOMP gets a foothold
The infection starts with a VBScript file sitting on the victim’s desktop. Securonix noted the sample used a randomized filename, which researchers suspect may have been intended to evade filename-based detection.
Windows Script Host executes the file. The script then builds five separate ways back into the system: four scheduled tasks plus one backup copy.
The four scheduled tasks:
Local Credential Manager
Network Audio Service
Windows Display Manager
Device Credential Handler
The fifth foothold:
The VBScript installer copies itself into the Startup folder as msdiag.vbs.
Windows Script Host launches this file automatically at every user logon.
This creates a persistence path independent of the four scheduled tasks.
If defenders remove the tasks but miss msdiag.vbs, the malware relaunches and rebuilds its execution chain.
Its files also stage in %LOCALAPPDATA%\WinDefendSvc, a folder named to resemble a Windows Defender component. This isn’t a separate foothold; it’s where the malware keeps the files those footholds rely on.
Deleting the visible desktop script does nothing to the Startup folder copy. Researchers warn that removing only one foothold can let the malware rebuild itself.
Cybersecurity essentials for any organization
Essential cybersecurity practices and tools every organization should implement today.
The two PowerShell modules behind the theft
Once persistence is set, TASK#STOMP runs two hidden PowerShell modules as separate processes. Each one handles a different part of the attack.
sys_loader.ps1 – the theft module
Decodes a hidden file called diag_pack.dat
Steals system metadata, business documents, Wi-Fi passwords, and clipboard content
Monitors the filesystem for newly modified files in real time
Takes screenshots on command
win_conn.ps1 – the backup channel
Decodes a second hidden file called win_conn_cfg.dat
Runs its own independent execution and collection capabilities
Document theft follows a set priority
Securonix found the modules steal documents in a specific order: Word first, then PDF, PowerPoint, and Excel, ahead of archive files. Beardslee said this priority points to corporate-document espionage rather than opportunistic crime.
A shared flaw in the watchdog design
The two modules are built to watch each other and restart their partner if it stops. Securonix found the same bug in both modules. The bug resets the tick counter inside the first check block. This leaves the second watchdog block as dead code that never executes.
Featured resource
The Cybersecurity Blueprint
Download this cybersecurity blueprint covering statistics, attack patterns, strategy selection, and implementation steps for businesses.
Several parts of this campaign remain genuinely unconfirmed. Securonix did confirm two C2 domains, corecloudfileshare[.]xyz and attachmentsharingdrive[.]xyz. Beyond that infrastructure, researchers have been direct about the limits of their findings. Open questions the researchers flagged:
Attribution: Beardslee stated that nothing in the code, infrastructure, or TTPs overlaps cleanly with a known APT’s toolkit. Securonix is not making an attribution claim.
Delivery vector: Researchers could not confirm how the VBScript first reached the victim. Their best estimate points to a phishing email carrying a ZIP or ISO/IMG attachment, based on comparable VBS-loader campaigns.
Campaign timeline: The malware backdates several of its own files to January 15, 2024. Beardslee confirmed this date is fabricated as an anti-forensic technique, not evidence of when the real campaign began.
The IranTenders domain: The script opens a Chrome window to an Iran-related tenders and contracts site. Securonix does not treat this domain as malicious and cautions against blocking it outright, since one decoy domain isn’t enough to confirm sector or regional targeting.
Attack component breakdown
Component
Function
Operational Risk
VBScript orchestrator
Initial execution via wscript.exe
Uses a randomized filename, suspected to evade detection
Four scheduled tasks
Persistence disguised as legitimate Windows services
Survives removal of the visible desktop script
Startup folder copy
Backup persistence, relaunches at every login
Independent of the scheduled tasks, survives their removal
sys_loader.ps1
Document theft, Wi-Fi and clipboard capture, screenshots
Primary data exfiltration channel
win_conn.ps1
Secondary command-and-control and remote execution
Redundant access if the primary channel is blocked
Strengthening endpoint defense against script-based backdoors
Hexnode covers this attack chain at three points: blocking script execution, detecting suspicious behavior, and controlling the access it could lead to.
Restricting script execution on Windows endpoints
Hexnode UEM limits which scripts and executables can run on managed Windows devices. For a threat like TASK#STOMP, this includes:
Enforcing execution policies: Deploy AppLocker and Application Permission Policies to block unapproved VBScript and PowerShell execution across endpoints.
On-demand remediation: Use the Execute Custom Script action to push automated cleanup and forensic scripts to infected machines.
Investigating suspicious PowerShell and scheduled task activity
Hexnode XDR investigates suspicious activity on managed Windows and macOS endpoints. For a threat like TASK#STOMP, this includes:
Flagging unusual PowerShell process behavior tied to a compromised endpoint
Correlating endpoint activity with MITRE ATT&CK mapping to reveal the attack’s method
Supporting kill, quarantine, and isolation actions once suspicious activity is confirmed
Cutting off access if a device is compromised
Hexnode IdP ties user identity to real-time device posture via Hexnode’s Device Trust Engine before granting access. For a threat like TASK#STOMP, this includes:
Blocking login attempts from devices flagged as non-compliant within the UEM
Revoking access to corporate applications automatically once XDR marks a workstation non-compliant after detecting backdoor activity
Continuously re-verifying device posture rather than checking it only at initial login
Should organizations block the IranTenders domain that TASK#STOMP opens?
Not on its own. Securonix does not consider the domain itself malicious and warns that one decoy site isn’t enough evidence to justify a blanket block.
Is TASK#STOMP linked to a known nation-state group?
No. Securonix found no overlap with any established APT toolkit and is not making an attribution claim at this time.
What’s the safest first step after finding a TASK#STOMP infection?
Preserve the malware’s files and scheduled-task definitions before touching anything. Then stop the running scripts and remove all five footholds in one coordinated pass.
Conclusion
TASK#STOMP shows how far attackers can get using nothing but native Windows components. No exotic malware, just VBScript, Task Scheduler, PowerShell, and dynamically compiled C# code working together.
Security teams should treat redundant persistence as the default assumption for script-based backdoors, not the exception. Removing one foothold without checking for the other four leaves the door open.
Script-based backdoors hide in plain sight.
See how Hexnode helps detect and contain suspicious endpoint activity.
A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.