Tuesday, 22 September 2026

Search
Latent Digest

TECHNOLOGY, TRACKED ACROSS DISCIPLINES

Security & Privacy

TASK#STOMP Backdoor Steals Documents, Wi-Fi Passwords, and More

A newly disclosed PowerShell backdoor campaign, TASK#STOMP, targets Windows hosts to exfiltrate business documents and sensitive credentials.

· 1 min read · 2 sources

Security researchers have disclosed a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised Windows hosts. The backdoor automatically collects and exfiltrates business documents, and it also watches the filesystem for new or edited files to grab them as they appear.

Beyond document theft, TASK#STOMP steals saved Wi-Fi passwords and clipboard text, and it can take screenshots. Both sources agree on these core capabilities, though The Hacker News emphasizes the automatic harvesting and filesystem monitoring, while Help Net Security notes the malware remains persistent to capture ongoing document changes.

The campaign highlights the growing use of PowerShell-based malware for stealthy data exfiltration, targeting both credentials and business-critical files. Organizations should monitor for unusual PowerShell activity and restrict script execution to mitigate such threats.

Sources · 2

  1. 01TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard DataThe Hacker News
  2. 02The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business filesHelp Net Security

More in Security & Privacy