Sophia
Hart

TASK#STOMP PowerShell Backdoor Steals Business Documents

Sophia Hart

Sep 22, 2026

6 min read

task#stomp powershell backdoor

TL; DR

  • TASK#STOMP starts with a VBScript file on the desktop, then creates four scheduled tasks and a Startup folder copy for redundant persistence.
  • Two hidden PowerShell modules steal business documents, Wi-Fi passwords, and clipboard data while keeping a second command channel open.
  • Securonix found no link to any known APT group and assesses this as a mid-tier operator based on reused, buggy code.
  • The malware prioritizes Word, PDF, PowerPoint, and Excel files, pointing toward targeted document theft rather than opportunistic crime.
  • The delivery method and full campaign scope remain unconfirmed, since researchers only analyzed one infected device.

Securonix Threat Research has disclosed a new campaign called TASK#STOMP. It centers on a PowerShell backdoor built to harvest sensitive data from compromised Windows hosts.

Researchers Akshay Gaikwad and Aaron Beardslee built their analysis from a single infected machine. They cannot yet say how many organizations the campaign has affected.

The backdoor searches drives for business documents, uploads them to attacker servers, and keeps watching for new files. It also steals Wi-Fi passwords, clipboard content, and screenshots, and runs remote commands on demand.

How TASK#STOMP gets a foothold

The infection starts with a VBScript file sitting on the victim’s desktop. Securonix noted the sample used a randomized filename, which researchers suspect may have been intended to evade filename-based detection.

Windows Script Host executes the file. The script then builds five separate ways back into the system: four scheduled tasks plus one backup copy.

The four scheduled tasks:

  • Local Credential Manager
  • Network Audio Service
  • Windows Display Manager
  • Device Credential Handler

The fifth foothold:

  • The VBScript installer copies itself into the Startup folder as msdiag.vbs.
  • Windows Script Host launches this file automatically at every user logon.
  • This creates a persistence path independent of the four scheduled tasks.
  • If defenders remove the tasks but miss msdiag.vbs, the malware relaunches and rebuilds its execution chain.

Its files also stage in %LOCALAPPDATA%\WinDefendSvc, a folder named to resemble a Windows Defender component. This isn’t a separate foothold; it’s where the malware keeps the files those footholds rely on.

Deleting the visible desktop script does nothing to the Startup folder copy. Researchers warn that removing only one foothold can let the malware rebuild itself.

The two PowerShell modules behind the theft

Once persistence is set, TASK#STOMP runs two hidden PowerShell modules as separate processes. Each one handles a different part of the attack.

sys_loader.ps1 – the theft module

  • Decodes a hidden file called diag_pack.dat
  • Steals system metadata, business documents, Wi-Fi passwords, and clipboard content
  • Monitors the filesystem for newly modified files in real time
  • Takes screenshots on command

win_conn.ps1 – the backup channel

  • Decodes a second hidden file called win_conn_cfg.dat
  • Sets up a persistent, secondary command-and-control channel
  • Runs its own independent execution and collection capabilities

Document theft follows a set priority

Securonix found the modules steal documents in a specific order: Word first, then PDF, PowerPoint, and Excel, ahead of archive files. Beardslee said this priority points to corporate-document espionage rather than opportunistic crime.

A shared flaw in the watchdog design

The two modules are built to watch each other and restart their partner if it stops. Securonix found the same bug in both modules. The bug resets the tick counter inside the first check block. This leaves the second watchdog block as dead code that never executes.

the cybersecurity blueprint

The Cybersecurity Blueprint

Download this cybersecurity blueprint covering statistics, attack patterns, strategy selection, and implementation steps for businesses.

DOWNLOAD

What this backdoor doesn’t tell us yet

Several parts of this campaign remain genuinely unconfirmed. Securonix did confirm two C2 domains, corecloudfileshare[.]xyz and attachmentsharingdrive[.]xyz. Beyond that infrastructure, researchers have been direct about the limits of their findings. Open questions the researchers flagged:

  • Attribution: Beardslee stated that nothing in the code, infrastructure, or TTPs overlaps cleanly with a known APT’s toolkit. Securonix is not making an attribution claim.
  • Delivery vector: Researchers could not confirm how the VBScript first reached the victim. Their best estimate points to a phishing email carrying a ZIP or ISO/IMG attachment, based on comparable VBS-loader campaigns.
  • Campaign timeline: The malware backdates several of its own files to January 15, 2024. Beardslee confirmed this date is fabricated as an anti-forensic technique, not evidence of when the real campaign began.
  • The IranTenders domain: The script opens a Chrome window to an Iran-related tenders and contracts site. Securonix does not treat this domain as malicious and cautions against blocking it outright, since one decoy domain isn’t enough to confirm sector or regional targeting.

Attack component breakdown

Component Function Operational Risk
VBScript orchestrator Initial execution via wscript.exe Uses a randomized filename, suspected to evade detection
Four scheduled tasks Persistence disguised as legitimate Windows services Survives removal of the visible desktop script
Startup folder copy Backup persistence, relaunches at every login Independent of the scheduled tasks, survives their removal
sys_loader.ps1 Document theft, Wi-Fi and clipboard capture, screenshots Primary data exfiltration channel
win_conn.ps1 Secondary command-and-control and remote execution Redundant access if the primary channel is blocked

Strengthening endpoint defense against script-based backdoors

Hexnode covers this attack chain at three points: blocking script execution, detecting suspicious behavior, and controlling the access it could lead to.

Restricting script execution on Windows endpoints

Hexnode UEM limits which scripts and executables can run on managed Windows devices. For a threat like TASK#STOMP, this includes:

  • Enforcing execution policies: Deploy AppLocker and Application Permission Policies to block unapproved VBScript and PowerShell execution across endpoints.
  • On-demand remediation: Use the Execute Custom Script action to push automated cleanup and forensic scripts to infected machines.

Investigating suspicious PowerShell and scheduled task activity

Hexnode XDR investigates suspicious activity on managed Windows and macOS endpoints. For a threat like TASK#STOMP, this includes:

  • Flagging unusual PowerShell process behavior tied to a compromised endpoint
  • Correlating endpoint activity with MITRE ATT&CK mapping to reveal the attack’s method
  • Supporting kill, quarantine, and isolation actions once suspicious activity is confirmed

Cutting off access if a device is compromised

Hexnode IdP ties user identity to real-time device posture via Hexnode’s Device Trust Engine before granting access. For a threat like TASK#STOMP, this includes:

  • Blocking login attempts from devices flagged as non-compliant within the UEM
  • Revoking access to corporate applications automatically once XDR marks a workstation non-compliant after detecting backdoor activity
  • Continuously re-verifying device posture rather than checking it only at initial login

Book a free demo and explore Hexnode today!

FAQs

Not on its own. Securonix does not consider the domain itself malicious and warns that one decoy site isn’t enough evidence to justify a blanket block.

No. Securonix found no overlap with any established APT toolkit and is not making an attribution claim at this time.

Preserve the malware’s files and scheduled-task definitions before touching anything. Then stop the running scripts and remove all five footholds in one coordinated pass.

Conclusion

TASK#STOMP shows how far attackers can get using nothing but native Windows components. No exotic malware, just VBScript, Task Scheduler, PowerShell, and dynamically compiled C# code working together.

Security teams should treat redundant persistence as the default assumption for script-based backdoors, not the exception. Removing one foothold without checking for the other four leaves the door open.

Share

Sophia Hart

A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.