{"id":1865,"date":"2026-09-22T10:41:27","date_gmt":"2026-09-22T05:11:27","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1865"},"modified":"2026-09-24T11:24:27","modified_gmt":"2026-09-24T05:54:27","slug":"taskstomp-powershell-backdoor-steals-business-documents","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/taskstomp-powershell-backdoor-steals-business-documents\/","title":{"rendered":"TASK#STOMP PowerShell Backdoor Steals Business Documents"},"content":{"rendered":"<p>Securonix Threat Research has disclosed a new campaign called TASK#STOMP. It centers on a PowerShell backdoor built to harvest sensitive data from compromised Windows hosts.<\/p>\n<p>Researchers Akshay Gaikwad and Aaron Beardslee built their analysis from a single infected machine. They cannot yet say how many organizations the campaign has affected.<\/p>\n<p>The backdoor searches drives for business documents, uploads them to attacker servers, and keeps watching for new files. It also steals Wi-Fi passwords, clipboard content, and screenshots, and runs remote commands on demand.<\/p>\n<h2>How TASK#STOMP gets a foothold<\/h2>\n<p>The infection starts with a VBScript file sitting on the victim&#8217;s desktop. Securonix noted the sample used a randomized filename, which researchers suspect may have been intended to evade filename-based detection.<\/p>\n<p>Windows Script Host executes the file. The script then builds five separate ways back into the system: four scheduled tasks plus one backup copy.<\/p>\n<h3>The four scheduled tasks:<\/h3>\n<ul>\n<li>Local Credential Manager<\/li>\n<li>Network Audio Service<\/li>\n<li>Windows Display Manager<\/li>\n<li>Device Credential Handler<\/li>\n<\/ul>\n<h3>The fifth foothold:<\/h3>\n<ul>\n<li>The VBScript installer copies itself into the Startup folder as msdiag.vbs.<\/li>\n<li>Windows Script Host launches this file automatically at every user logon.<\/li>\n<li>This creates a persistence path independent of the four scheduled tasks.<\/li>\n<li>If defenders remove the tasks but miss msdiag.vbs, the malware relaunches and rebuilds its execution chain.<\/li>\n<\/ul>\n<p>Its files also stage in %LOCALAPPDATA%\\WinDefendSvc, a folder named to resemble a Windows Defender component. This isn&#8217;t a separate foothold; it&#8217;s where the malware keeps the files those footholds rely on.<\/p>\n<p>Deleting the visible desktop script does nothing to the Startup folder copy. Researchers warn that removing only one foothold can let the <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-malware\/\">malware<\/a> rebuild itself.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-essentials.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Cybersecurity essentials for any organization<\/h4><p>Essential cybersecurity practices and tools every organization should implement today.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/cybersecurity-essentials-for-any-organization\/\" aria-label=\"Cybersecurity essentials for any organization\"><\/a><\/div><\/div><\/div>\n<h2>The two PowerShell modules behind the theft<\/h2>\n<p>Once persistence is set, TASK#STOMP runs two hidden PowerShell modules as separate processes. Each one handles a different part of the attack.<\/p>\n<h3>sys_loader.ps1 &#8211; the theft module<\/h3>\n<ul>\n<li>Decodes a hidden file called diag_pack.dat<\/li>\n<li>Steals system metadata, business documents, Wi-Fi passwords, and clipboard content<\/li>\n<li>Monitors the filesystem for newly modified files in real time<\/li>\n<li>Takes screenshots on command<\/li>\n<\/ul>\n<h3>win_conn.ps1 &#8211; the backup channel<\/h3>\n<ul>\n<li>Decodes a second hidden file called win_conn_cfg.dat<\/li>\n<li>Sets up a persistent, secondary <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-command-and-control-c2\/\">command-and-control<\/a> channel<\/li>\n<li>Runs its own independent execution and collection capabilities<\/li>\n<\/ul>\n<h3>Document theft follows a set priority<\/h3>\n<p>Securonix found the modules steal documents in a specific order: Word first, then PDF, PowerPoint, and Excel, ahead of archive files. Beardslee said this priority points to corporate-document espionage rather than opportunistic crime.<\/p>\n<h3>A shared flaw in the watchdog design<\/h3>\n<p>The two modules are built to watch each other and restart their partner if it stops. Securonix found the same bug in both modules. The bug resets the tick counter inside the first check block. This leaves the second watchdog block as dead code that never executes.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint.png?format=webp\" class=\"resource-box__image\" alt=\"the cybersecurity blueprint\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint.png?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint-300x225.png?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint-768x576.png?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint-133x100.png?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"the cybersecurity blueprint\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            The Cybersecurity Blueprint\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Download this cybersecurity blueprint covering statistics, attack patterns, strategy selection, and implementation steps for businesses.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/the-cybersecurity-blueprint-how-to-adopt-the-right-cybersecurity-strategy-for-your-business\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>What this backdoor doesn&#8217;t tell us yet<\/h2>\n<p>Several parts of this campaign remain genuinely unconfirmed. Securonix did confirm two C2 domains, corecloudfileshare[.]xyz and attachmentsharingdrive[.]xyz. Beyond that infrastructure, researchers have been direct about the limits of their findings. Open questions the researchers flagged:<\/p>\n<ul>\n<li><strong>Attribution:<\/strong> Beardslee stated that nothing in the code, infrastructure, or TTPs overlaps cleanly with a known APT&#8217;s toolkit. Securonix is not making an attribution claim.<\/li>\n<li><strong>Delivery vector:<\/strong> Researchers could not confirm how the VBScript first reached the victim. Their best estimate points to a phishing email carrying a ZIP or ISO\/IMG attachment, based on comparable VBS-loader campaigns.<\/li>\n<li><strong>Campaign timeline:<\/strong> The malware backdates several of its own files to January 15, 2024. Beardslee confirmed this date is fabricated as an anti-forensic technique, not evidence of when the real campaign began.<\/li>\n<li><strong>The IranTenders domain:<\/strong> The script opens a Chrome window to an Iran-related tenders and contracts site. Securonix does not treat this domain as malicious and cautions against blocking it outright, since one decoy domain isn&#8217;t enough to confirm sector or regional targeting.<\/li>\n<\/ul>\n<h3>Attack component breakdown<\/h3>\n<table style=\"width: 100%;\">\n<thead>\n<tr>\n<th style=\"width: 20.1903%; text-align: left;\"><strong>Component<\/strong><\/th>\n<th style=\"width: 38.2664%; text-align: left;\"><strong>Function<\/strong><\/th>\n<th style=\"width: 40.4862%; text-align: left;\"><strong>Operational Risk<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 20.1903%;\">VBScript orchestrator<\/td>\n<td style=\"width: 38.2664%;\">Initial execution via wscript.exe<\/td>\n<td style=\"width: 40.4862%;\">Uses a randomized filename, suspected to evade detection<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.1903%;\">Four scheduled tasks<\/td>\n<td style=\"width: 38.2664%;\">Persistence disguised as legitimate Windows services<\/td>\n<td style=\"width: 40.4862%;\">Survives removal of the visible desktop script<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.1903%;\">Startup folder copy<\/td>\n<td style=\"width: 38.2664%;\">Backup persistence, relaunches at every login<\/td>\n<td style=\"width: 40.4862%;\">Independent of the scheduled tasks, survives their removal<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.1903%;\">sys_loader.ps1<\/td>\n<td style=\"width: 38.2664%;\">Document theft, Wi-Fi and clipboard capture, screenshots<\/td>\n<td style=\"width: 40.4862%;\">Primary data exfiltration channel<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.1903%;\">win_conn.ps1<\/td>\n<td style=\"width: 38.2664%;\">Secondary command-and-control and remote execution<\/td>\n<td style=\"width: 40.4862%;\">Redundant access if the primary channel is blocked<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Strengthening endpoint defense against script-based backdoors<\/h2>\n<p><a href=\"https:\/\/www.hexnode.com\/\">Hexnode<\/a> covers this attack chain at three points: blocking script execution, detecting suspicious behavior, and controlling the access it could lead to.<\/p>\n<h3>Restricting script execution on Windows endpoints<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> limits which scripts and executables can run on managed Windows devices. For a threat like TASK#STOMP, this includes:<\/p>\n<ul>\n<li><strong>Enforcing execution policies:<\/strong> Deploy AppLocker and Application Permission Policies to block unapproved VBScript and PowerShell execution across endpoints.<\/li>\n<li><strong>On-demand remediation:<\/strong> Use the Execute Custom Script action to push automated cleanup and forensic scripts to infected machines.<\/li>\n<\/ul>\n<h3>Investigating suspicious PowerShell and scheduled task activity<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> investigates suspicious activity on managed Windows and macOS endpoints. For a threat like TASK#STOMP, this includes:<\/p>\n<ul>\n<li>Flagging unusual PowerShell process behavior tied to a compromised endpoint<\/li>\n<li>Correlating endpoint activity with <a href=\"https:\/\/www.hexnode.com\/blogs\/mitre-attack-framework\/\">MITRE ATT&amp;CK<\/a> mapping to reveal the attack&#8217;s method<\/li>\n<li>Supporting kill, quarantine, and isolation actions once suspicious activity is confirmed<\/li>\n<\/ul>\n<h3>Cutting off access if a device is compromised<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/idp\/\">Hexnode IdP<\/a> ties user identity to real-time device posture via Hexnode&#8217;s Device Trust Engine before granting access. For a threat like TASK#STOMP, this includes:<\/p>\n<ul>\n<li>Blocking login attempts from devices flagged as non-compliant within the UEM<\/li>\n<li>Revoking access to corporate applications automatically once XDR marks a workstation non-compliant after detecting backdoor activity<\/li>\n<li>Continuously re-verifying device posture rather than checking it only at initial login<\/li>\n<\/ul>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tBook a free demo and explore Hexnode today!<\/a>\r\n    \t\t<\/center><div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Should organizations block the IranTenders domain that TASK#STOMP opens?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Not on its own. Securonix does not consider the domain itself malicious and warns that one decoy site isn&#8217;t enough evidence to justify a blanket block.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Is TASK#STOMP linked to a known nation-state group?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. Securonix found no overlap with any established APT toolkit and is not making an attribution claim at this time.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What&#8217;s the safest first step after finding a TASK#STOMP infection?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Preserve the malware&#8217;s files and scheduled-task definitions before touching anything. Then stop the running scripts and remove all five footholds in one coordinated pass.<\/p>\n<\/div><\/div><\/div><\/div><\/div><\/p>\n<h3>Conclusion<\/h3>\n<p>TASK#STOMP shows how far attackers can get using nothing but native Windows components. No exotic malware, just VBScript, Task Scheduler, PowerShell, and dynamically compiled C# code working together.<\/p>\n<p>Security teams should treat redundant persistence as the default assumption for script-based backdoors, not the exception. Removing one foothold without checking for the other four leaves the door open.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Script-based backdoors hide in plain sight. <\/h5><p>See how Hexnode helps detect and contain suspicious endpoint activity.<\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Securonix Threat Research has disclosed a new campaign called TASK#STOMP. It centers on a PowerShell&#8230;<\/p>\n","protected":false},"author":5,"featured_media":1886,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15,16],"class_list":["post-1865","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware","category-windows","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>TASK#STOMP PowerShell Backdoor Steals Business Documents<\/title>\n<meta name=\"description\" content=\"TASK#STOMP PowerShell backdoor steals business documents, Wi-Fi passwords, and clipboard data through redundant, hard-to-remove persistence.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/taskstomp-powershell-backdoor-steals-business-documents\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"TASK#STOMP PowerShell Backdoor Steals Business Documents\" \/>\n<meta property=\"og:description\" content=\"TASK#STOMP PowerShell backdoor steals business documents, Wi-Fi passwords, and clipboard data through redundant, hard-to-remove persistence.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/taskstomp-powershell-backdoor-steals-business-documents\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-22T05:11:27+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-24T05:54:27+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/taskstomp-powershell-backdoor.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/taskstomp-powershell-backdoor-steals-business-documents\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/taskstomp-powershell-backdoor-steals-business-documents\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"TASK#STOMP PowerShell Backdoor Steals Business Documents\",\"datePublished\":\"2026-09-22T05:11:27+00:00\",\"dateModified\":\"2026-09-24T05:54:27+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/taskstomp-powershell-backdoor-steals-business-documents\\\/\"},\"wordCount\":1201,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/taskstomp-powershell-backdoor-steals-business-documents\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/taskstomp-powershell-backdoor.jpeg?format=webp\",\"articleSection\":[\"Malware\",\"Windows\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/taskstomp-powershell-backdoor-steals-business-documents\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/taskstomp-powershell-backdoor-steals-business-documents\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/taskstomp-powershell-backdoor-steals-business-documents\\\/\",\"name\":\"TASK#STOMP PowerShell Backdoor Steals Business Documents\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/taskstomp-powershell-backdoor-steals-business-documents\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/taskstomp-powershell-backdoor-steals-business-documents\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/taskstomp-powershell-backdoor.jpeg?format=webp\",\"datePublished\":\"2026-09-22T05:11:27+00:00\",\"dateModified\":\"2026-09-24T05:54:27+00:00\",\"description\":\"TASK#STOMP PowerShell backdoor steals business documents, Wi-Fi passwords, and clipboard data through redundant, hard-to-remove persistence.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/taskstomp-powershell-backdoor-steals-business-documents\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/taskstomp-powershell-backdoor-steals-business-documents\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/taskstomp-powershell-backdoor-steals-business-documents\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/taskstomp-powershell-backdoor.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/taskstomp-powershell-backdoor.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"task#stomp powershell backdoor\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/taskstomp-powershell-backdoor-steals-business-documents\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"TASK#STOMP PowerShell Backdoor Steals Business Documents\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"description\":\"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"TASK#STOMP PowerShell Backdoor Steals Business Documents","description":"TASK#STOMP PowerShell backdoor steals business documents, Wi-Fi passwords, and clipboard data through redundant, hard-to-remove persistence.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/taskstomp-powershell-backdoor-steals-business-documents\/","og_locale":"en_US","og_type":"article","og_title":"TASK#STOMP PowerShell Backdoor Steals Business Documents","og_description":"TASK#STOMP PowerShell backdoor steals business documents, Wi-Fi passwords, and clipboard data through redundant, hard-to-remove persistence.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/taskstomp-powershell-backdoor-steals-business-documents\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-22T05:11:27+00:00","article_modified_time":"2026-09-24T05:54:27+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/taskstomp-powershell-backdoor.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/taskstomp-powershell-backdoor-steals-business-documents\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/taskstomp-powershell-backdoor-steals-business-documents\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"TASK#STOMP PowerShell Backdoor Steals Business Documents","datePublished":"2026-09-22T05:11:27+00:00","dateModified":"2026-09-24T05:54:27+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/taskstomp-powershell-backdoor-steals-business-documents\/"},"wordCount":1201,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/taskstomp-powershell-backdoor-steals-business-documents\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/taskstomp-powershell-backdoor.jpeg?format=webp","articleSection":["Malware","Windows"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/taskstomp-powershell-backdoor-steals-business-documents\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/taskstomp-powershell-backdoor-steals-business-documents\/","url":"https:\/\/www.hexnode.com\/threat-watch\/taskstomp-powershell-backdoor-steals-business-documents\/","name":"TASK#STOMP PowerShell Backdoor Steals Business Documents","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/taskstomp-powershell-backdoor-steals-business-documents\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/taskstomp-powershell-backdoor-steals-business-documents\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/taskstomp-powershell-backdoor.jpeg?format=webp","datePublished":"2026-09-22T05:11:27+00:00","dateModified":"2026-09-24T05:54:27+00:00","description":"TASK#STOMP PowerShell backdoor steals business documents, Wi-Fi passwords, and clipboard data through redundant, hard-to-remove persistence.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/taskstomp-powershell-backdoor-steals-business-documents\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/taskstomp-powershell-backdoor-steals-business-documents\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/taskstomp-powershell-backdoor-steals-business-documents\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/taskstomp-powershell-backdoor.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/taskstomp-powershell-backdoor.jpeg?format=webp","width":1340,"height":700,"caption":"task#stomp powershell backdoor"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/taskstomp-powershell-backdoor-steals-business-documents\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"TASK#STOMP PowerShell Backdoor Steals Business Documents"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"description":"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1865","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1865"}],"version-history":[{"count":5,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1865\/revisions"}],"predecessor-version":[{"id":1931,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1865\/revisions\/1931"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1886"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1865"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1865"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}