Securonix Threat Research has released new research on TASK#STOMP, a Windows backdoor designed to maintain long-term access and continuously steal business documents. The malware targets files across every fixed drive, monitors for new or modified documents and gives attackers ongoing remote access to the infected system.
Key findings include:
- TASK#STOMP combines scheduled tasks, a Startup-folder launcher and rotating Windows-style task names to maintain persistence and evade detection.
- Two PowerShell modules provide redundant command-and-control channels and can steal documents, saved Wi-Fi passwords and clipboard contents, capture screenshots and execute remote commands.
- Its full capabilities may be missed in endpoint telemetry, but the broader chain of script execution, task creation, timestomping and runtime compilation provides defenders with strong detection opportunities.
You can read the research here: https://www.securonix.com/blog/task-stomp-powershell-backdoor-document-theft-remote-access
Related
This entry was posted on September 21, 2026 at 10:00 am and is filed under Commentary. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Securonix Uncovers Windows Backdoor That Enables Continuous Document Theft
Securonix Threat Research has released new research on TASK#STOMP, a Windows backdoor designed to maintain long-term access and continuously steal business documents. The malware targets files across every fixed drive, monitors for new or modified documents and gives attackers ongoing remote access to the infected system.
Key findings include:
You can read the research here: https://www.securonix.com/blog/task-stomp-powershell-backdoor-document-theft-remote-access
Share this:
Like this:
Related
This entry was posted on September 21, 2026 at 10:00 am and is filed under Commentary. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.