Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
PowerShell Exploited in New TASK#STOMP Cyber Intrusion

PowerShell Exploited in New TASK#STOMP Cyber Intrusion

Posted on September 22, 2026 By CWS

A newly analyzed Windows backdoor known as TASK#STOMP has emerged, transforming built-in tools into a robust spying operation. This malware leverages PowerShell to collect sensitive information, exploiting ordinary utilities for malicious purposes.

Key Features of TASK#STOMP

TASK#STOMP initiates its attack through a Visual Basic Script (VBS) installer, which uses hidden PowerShell scripts and scheduled tasks to gather business documents, Wi-Fi credentials, clipboard data, and screenshots. The infection begins with a randomly named VBS file in a location accessible to the user. However, the exact delivery method remains unconfirmed, with potential vectors including phishing, browser downloads, or other means.

Once deployed, the backdoor establishes several persistence mechanisms to survive system reboots or partial cleanups. According to a report from Securonix shared with Cyber Security News, TASK#STOMP is a fully functional PowerShell backdoor designed for ongoing data collection and remote control.

Operational Details and Risks

The primary module of TASK#STOMP scans fixed drives for documents such as Word, PDF, PowerPoint, Excel, and archives, particularly targeting files created or modified within the past year. It uploads selected files to command servers while avoiding those larger than 500 MB. This malware also monitors drives for any changes, capturing new or altered files.

Additionally, TASK#STOMP executes Windows netsh commands to list and expose stored wireless profiles and passwords in plain text. Clipboard contents are extracted, transmitted, and cleared, and screenshots can be taken on demand. These features render TASK#STOMP a comprehensive data-gathering tool, similar to other credential-harvesting campaigns.

Persistence and Mitigation Strategies

To ensure persistence, TASK#STOMP sets up four scheduled tasks using XML files in a user-writable AppData folder, adding a script named msdiag.vbs to the Startup folder. These tasks are named to resemble legitimate Windows services, complicating detection.

Security teams are advised to scrutinize VBS or Windows Script Host processes that create tasks from AppData, especially when followed by concealed PowerShell and compiler activities. Logging PowerShell Script Blocks, AMSI records, Task Scheduler logs, and endpoint file events can be crucial for reconstructing the infection chain.

Conclusion and Recommendations

The sophistication of TASK#STOMP underscores the importance of behavioral detection in cybersecurity. To mitigate threats, organizations should preserve task XML and staged files, terminate active VBS and PowerShell processes, remove all scheduled tasks and Startup entries, and block known malicious infrastructure. Ensuring thorough system checks and reboots is essential to prevent re-infection.

Indicators of compromise and detailed analysis are vital for understanding and countering such advanced threats, reinforcing the need for proactive cybersecurity measures.

Cyber Security News Tags:Backdoor, cyber attack, Cybersecurity, data theft, Malware, network security, PowerShell, scheduled tasks, Securonix, TASKSTOMP, VBS, Wi-Fi passwords, Windows

Post navigation

Previous Post: Malicious npm Package Targets Twilio Developers
Next Post: Critical AI Gateway Flaw Exposes Bifrost to Command Attacks

Related Posts

NAKIVO v11.1 Introduces Stronger Protection for Virtual Environments NAKIVO v11.1 Introduces Stronger Protection for Virtual Environments Cyber Security News
LucidRook Malware Masquerades as Security Software in Taiwan LucidRook Malware Masquerades as Security Software in Taiwan Cyber Security News
Microsoft Defender for Office 365 New Dashboard to Provide More Details Across a Range of Threat Vectors Microsoft Defender for Office 365 New Dashboard to Provide More Details Across a Range of Threat Vectors Cyber Security News
Instagram Addresses Password Reset Vulnerability Instagram Addresses Password Reset Vulnerability Cyber Security News
Windows Update Installs LG App with McAfee Ads Windows Update Installs LG App with McAfee Ads Cyber Security News
New Supply Chain Attack Targets Legitimate npm Package with 45,000 Weekly Downloads New Supply Chain Attack Targets Legitimate npm Package with 45,000 Weekly Downloads Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Veeam Agent Vulnerability Exploited for SYSTEM Privileges
  • Critical AI Gateway Flaw Exposes Bifrost to Command Attacks
  • PowerShell Exploited in New TASK#STOMP Cyber Intrusion
  • Malicious npm Package Targets Twilio Developers
  • Enhancing SOC Efficiency with Threat Intelligence

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Veeam Agent Vulnerability Exploited for SYSTEM Privileges
  • Critical AI Gateway Flaw Exposes Bifrost to Command Attacks
  • PowerShell Exploited in New TASK#STOMP Cyber Intrusion
  • Malicious npm Package Targets Twilio Developers
  • Enhancing SOC Efficiency with Threat Intelligence

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark