TASK#STOMP Backdoor Steals Documents, Wi-Fi Passwords, and More
A newly disclosed PowerShell backdoor campaign, TASK#STOMP, targets Windows hosts to exfiltrate business documents and sensitive credentials.
Security researchers have disclosed a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised Windows hosts. The backdoor automatically collects and exfiltrates business documents, and it also watches the filesystem for new or edited files to grab them as they appear.
Beyond document theft, TASK#STOMP steals saved Wi-Fi passwords and clipboard text, and it can take screenshots. Both sources agree on these core capabilities, though The Hacker News emphasizes the automatic harvesting and filesystem monitoring, while Help Net Security notes the malware remains persistent to capture ongoing document changes.
The campaign highlights the growing use of PowerShell-based malware for stealthy data exfiltration, targeting both credentials and business-critical files. Organizations should monitor for unusual PowerShell activity and restrict script execution to mitigate such threats.
Sources · 2
More in Security & Privacy
WordPress Click2Shell CSRF Flaw Could Let Attackers Run PHP Code
A newly disclosed cross-site request forgery vulnerability in WordPress Core, with a public proof-of-concept, can let attackers execute PHP on the server.
Film Torrents Carry New Malware, Victims Found in Kenya and Uganda
Cybercriminals are using popular movie torrents to distribute fresh malware, with confirmed infections in East Africa.
CrowdSec Breach: TanStack npm Attack Exposed 170 Private Repos
CrowdSec says an attacker used a former employee's still-active GitHub access to copy 170 private repositories, tracing the intrusion to the TanStack npm attack.
CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog
The agency's move signals active attacks and pressures federal agencies to patch quickly.