Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
PowerShell Exploited in New TASK#STOMP Cyber Intrusion

PowerShell Exploited in New TASK#STOMP Cyber Intrusion

Posted on September 22, 2026 By CWS

A newly analyzed Windows backdoor known as TASK#STOMP has emerged, transforming built-in tools into a robust spying operation. This malware leverages PowerShell to collect sensitive information, exploiting ordinary utilities for malicious purposes.

Key Features of TASK#STOMP

TASK#STOMP initiates its attack through a Visual Basic Script (VBS) installer, which uses hidden PowerShell scripts and scheduled tasks to gather business documents, Wi-Fi credentials, clipboard data, and screenshots. The infection begins with a randomly named VBS file in a location accessible to the user. However, the exact delivery method remains unconfirmed, with potential vectors including phishing, browser downloads, or other means.

Once deployed, the backdoor establishes several persistence mechanisms to survive system reboots or partial cleanups. According to a report from Securonix shared with Cyber Security News, TASK#STOMP is a fully functional PowerShell backdoor designed for ongoing data collection and remote control.

Operational Details and Risks

The primary module of TASK#STOMP scans fixed drives for documents such as Word, PDF, PowerPoint, Excel, and archives, particularly targeting files created or modified within the past year. It uploads selected files to command servers while avoiding those larger than 500 MB. This malware also monitors drives for any changes, capturing new or altered files.

Additionally, TASK#STOMP executes Windows netsh commands to list and expose stored wireless profiles and passwords in plain text. Clipboard contents are extracted, transmitted, and cleared, and screenshots can be taken on demand. These features render TASK#STOMP a comprehensive data-gathering tool, similar to other credential-harvesting campaigns.

Persistence and Mitigation Strategies

To ensure persistence, TASK#STOMP sets up four scheduled tasks using XML files in a user-writable AppData folder, adding a script named msdiag.vbs to the Startup folder. These tasks are named to resemble legitimate Windows services, complicating detection.

Security teams are advised to scrutinize VBS or Windows Script Host processes that create tasks from AppData, especially when followed by concealed PowerShell and compiler activities. Logging PowerShell Script Blocks, AMSI records, Task Scheduler logs, and endpoint file events can be crucial for reconstructing the infection chain.

Conclusion and Recommendations

The sophistication of TASK#STOMP underscores the importance of behavioral detection in cybersecurity. To mitigate threats, organizations should preserve task XML and staged files, terminate active VBS and PowerShell processes, remove all scheduled tasks and Startup entries, and block known malicious infrastructure. Ensuring thorough system checks and reboots is essential to prevent re-infection.

Indicators of compromise and detailed analysis are vital for understanding and countering such advanced threats, reinforcing the need for proactive cybersecurity measures.

Cyber Security News Tags:Backdoor, cyber attack, Cybersecurity, data theft, Malware, network security, PowerShell, scheduled tasks, Securonix, TASKSTOMP, VBS, Wi-Fi passwords, Windows

Post navigation

Previous Post: Malicious npm Package Targets Twilio Developers

Related Posts

McLaren Health Care Data Breach Exposes 743,000 People Personal Information McLaren Health Care Data Breach Exposes 743,000 People Personal Information Cyber Security News
Hackers use Fake Cloudflare Verification Screen to Trick Users into Executing Malware Hackers use Fake Cloudflare Verification Screen to Trick Users into Executing Malware Cyber Security News
SentinelOne Global Service Outage Root Cause Revealed SentinelOne Global Service Outage Root Cause Revealed Cyber Security News
800K+ GNU InetUtils telnetd Instances Exposed to RCE Attacks 800K+ GNU InetUtils telnetd Instances Exposed to RCE Attacks Cyber Security News
Hackers Compromised Official Gaming Mouse Software to Deliver Windows-based Xred Malware Hackers Compromised Official Gaming Mouse Software to Deliver Windows-based Xred Malware Cyber Security News
Hackers Abusing Legitimate Cloud and CDN Platforms to Host Phishing Kits Hackers Abusing Legitimate Cloud and CDN Platforms to Host Phishing Kits Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • PowerShell Exploited in New TASK#STOMP Cyber Intrusion
  • Malicious npm Package Targets Twilio Developers
  • Enhancing SOC Efficiency with Threat Intelligence
  • Urgent WordPress Update Fixes Major Security Vulnerability
  • Aembit Integrates Okta’s Cross App Access for AI Control

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • PowerShell Exploited in New TASK#STOMP Cyber Intrusion
  • Malicious npm Package Targets Twilio Developers
  • Enhancing SOC Efficiency with Threat Intelligence
  • Urgent WordPress Update Fixes Major Security Vulnerability
  • Aembit Integrates Okta’s Cross App Access for AI Control

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark