AI Weekly Malaysia

Back to items Summaries

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

ID
26852
Status
summarized
Published
21 Sep 2026, 10:15 PM
Fetched
21 Sep 2026, 11:04 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/taskstomp-powershell-backdoor-steals.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.0
Created
21 Sep 2026, 11:07 PM
Tags
Audience
developers

What happened

Securonix researchers disclosed a campaign called TASK#STOMP that delivers a PowerShell backdoor via an encoded VBScript file on the victim's desktop. The backdoor exfiltrates business documents, Wi-Fi passwords, clipboard contents, and screenshots, using scheduled tasks disguised as legitimate OS services (e.g., 'Local Credential Manager', 'Network Audio Service') for persistence, plus a backup method via the Windows Startup folder. Initial access is unclear but likely phishing or social engineering.

Why it matters

This is a standard Windows endpoint malware campaign with no direct connection to AI, agents, or developer tooling this audience ships with. There is no specific action for builders to take beyond existing endpoint hygiene practices.

Discussion angle

Brief mention only: the persistence techniques (scheduled tasks with fake service names, timestomping, redundant C2) are worth noting as examples of how malware blends into normal OS activity — useful awareness for anyone running Windows-based infrastructure.

Top