Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
PowerShell Backdoor TASK#STOMP Steals Sensitive Data

PowerShell Backdoor TASK#STOMP Steals Sensitive Data

Posted on September 21, 2026 By CWS

Cybersecurity experts have unveiled details of a sophisticated cyber attack known as TASK#STOMP, which utilizes a PowerShell backdoor to extract sensitive data from infected systems. This new threat, identified by Securonix researchers Akshay Gaikwad and Aaron Beardslee, poses significant risks by targeting business documents, Wi-Fi credentials, clipboard data, and more.

How TASK#STOMP Infiltrates Systems

The initial entry point for TASK#STOMP is through the execution of an encoded VBScript file, ’95c9050t66.vbs’, on the victim’s desktop via ‘wscript.exe’. Although the exact method of delivery is unclear, phishing or social engineering are suspected. The script establishes persistence and initiates further stages of the attack, masquerading as legitimate system processes to avoid detection.

Persistence is maintained through several methods, including scheduled tasks named to mimic regular system activities. Additionally, a backup persistence mechanism is implemented using the Windows Startup folder, ensuring the backdoor reloads upon user login.

Technical Mechanisms and Evasion Strategies

Once installed, TASK#STOMP executes PowerShell commands to eliminate any competing processes and ensures a single active session. The malware employs techniques such as timestamp modification and stealthy execution to evade forensic scrutiny, using multiple persistence strategies to ensure continued operation even if partially neutralized.

The attack deploys two PowerShell scripts: ‘sys_loader.ps1’ and ‘win_conn.ps1’. The former decodes and executes document-theft payloads, while the latter establishes a persistent command and control (C2) connection. These scripts support redundant operations, with each monitoring the other to maintain ongoing functionality.

Impact and Future Implications

The ultimate aim of TASK#STOMP is to enable persistent data theft, including document exfiltration and credential capture, while maintaining a low profile. The attack concludes with a user-facing action, opening Google Chrome to a specific Iranian tender database, although the intent remains unclear.

The operation exemplifies how threat actors exploit native Windows tools like PowerShell and Task Scheduler to integrate malicious activities within legitimate administrative processes. By avoiding traditional executable payloads, TASK#STOMP complicates detection and analysis, posing a significant challenge for cybersecurity defenses.

As the cybersecurity landscape evolves, understanding and mitigating such advanced threats remain a priority for protecting sensitive information from unauthorized access.

The Hacker News Tags:C2 servers, clipboard data, cyber attack, Cybersecurity, data theft, endpoint security, Malware, persistence methods, PowerShell, security threat, Securonix, task scheduler, VBScript, Wi-Fi passwords, Windows Script Host

Post navigation

Previous Post: ChatGPT Ad Tracking Cookie Raises Privacy Concerns
Next Post: Fake LastPass App Distributes Rapuncel Malware

Related Posts

Dashlane Alerts Users of Recent Security Breach Dashlane Alerts Users of Recent Security Breach The Hacker News
Security Platforms: A Solution for Mid-Market Needs Security Platforms: A Solution for Mid-Market Needs The Hacker News
Microsoft Mitigates Record 15.72 Tbps DDoS Attack Driven by AISURU Botnet Microsoft Mitigates Record 15.72 Tbps DDoS Attack Driven by AISURU Botnet The Hacker News
Microsoft Addresses Record 622 Vulnerabilities, Including Two Critical Zero-Days Microsoft Addresses Record 622 Vulnerabilities, Including Two Critical Zero-Days The Hacker News
ZAST.AI Secures M to Enhance AI-Driven Code Security ZAST.AI Secures $6M to Enhance AI-Driven Code Security The Hacker News
Why CISOs Must Rethink Incident Remediation Why CISOs Must Rethink Incident Remediation The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Probes Teams Calling Disruption Affecting Users
  • Cyberattacks Target Colorado Water Utilities’ OT Systems
  • Microsoft Entra ID to End SMS Sign-In by 2027
  • Fake LastPass App Distributes Rapuncel Malware
  • PowerShell Backdoor TASK#STOMP Steals Sensitive Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Probes Teams Calling Disruption Affecting Users
  • Cyberattacks Target Colorado Water Utilities’ OT Systems
  • Microsoft Entra ID to End SMS Sign-In by 2027
  • Fake LastPass App Distributes Rapuncel Malware
  • PowerShell Backdoor TASK#STOMP Steals Sensitive Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark