TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
- ID
- 26852
- Status
- summarized
- Published
- 21 Sep 2026, 10:15 PM
- Fetched
- 21 Sep 2026, 11:04 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/taskstomp-powershell-backdoor-steals.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.0
- Created
- 21 Sep 2026, 11:07 PM
- Tags
- Audience
- developers
What happened
Securonix researchers disclosed a campaign called TASK#STOMP that delivers a PowerShell backdoor via an encoded VBScript file on the victim's desktop. The backdoor exfiltrates business documents, Wi-Fi passwords, clipboard contents, and screenshots, using scheduled tasks disguised as legitimate OS services (e.g., 'Local Credential Manager', 'Network Audio Service') for persistence, plus a backup method via the Windows Startup folder. Initial access is unclear but likely phishing or social engineering.
Why it matters
This is a standard Windows endpoint malware campaign with no direct connection to AI, agents, or developer tooling this audience ships with. There is no specific action for builders to take beyond existing endpoint hygiene practices.
Discussion angle
Brief mention only: the persistence techniques (scheduled tasks with fake service names, timestomping, redundant C2) are worth noting as examples of how malware blends into normal OS activity — useful awareness for anyone running Windows-based infrastructure.