Skip to main content
The Wire
CyberNews by Zentrya One
Malware

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

TASK#STOMP is a new PowerShell backdoor that steals business documents, Wi-Fi passwords and clipboard data while using scheduled tasks and dual C2 servers for persistent access.

Cybersecurity researchers have uncovered a new Windows malware campaign dubbed TASK#STOMP, which deploys a PowerShell-based backdoor capable of continuously stealing business documents, saved Wi-Fi passwords, clipboard contents, screenshots, and other sensitive information.

Researchers at Securonix say the malware relies heavily on legitimate Windows components, including VBScript, PowerShell, Task Scheduler, and netsh, helping malicious activity blend with normal system operations.

How TASK#STOMP Works

The observed infection begins when wscript.exe executes an encoded VBScript file placed on the victim's desktop.

The exact initial delivery method remains unknown. Researchers say phishing or social engineering is possible, but this has not been confirmed.

The attack chain follows:

Malicious VBScript → Scheduled Tasks → PowerShell Loaders → Backdoor Execution → Data Theft → Dual C2 Communication

The malware creates multiple scheduled tasks with legitimate-looking names such as:

  • Local Credential Manager
  • Network Audio Service
  • Windows Display Manager
  • Device Credential Handler

It also places msdiag.vbs inside the Windows Startup folder, providing an additional persistence mechanism whenever the user logs in.

Two PowerShell Backdoor Components

TASK#STOMP launches two primary PowerShell components:

Component Purpose
sys_loader.ps1 Loads the main surveillance and data-stealing payload
win_conn.ps1 Maintains a secondary C2 and remote-command channel

The components decode payloads stored inside diag_pack.dat and win_conn_cfg.dat.

They are also designed to monitor one another and attempt to restore functionality if one component stops, providing additional resilience.

What Can TASK#STOMP Steal?

Once active, the backdoor can:

  • Search for and exfiltrate Word, PDF, PowerPoint, Excel and archive files
  • Monitor the filesystem for newly created or modified documents
  • Extract saved Wi-Fi passwords
  • Capture clipboard contents
  • Take screenshots
  • Collect system information
  • Execute arbitrary PowerShell commands
  • Download and execute additional attacker instructions

The malware uses commands such as netsh wlan show profile ... key=clear to retrieve accessible saved Wi-Fi credentials.

This makes TASK#STOMP particularly concerning for corporate environments because it is designed for continuous collection, rather than simply stealing files once and exiting.

Dual C2 Infrastructure

Researchers identified two command-and-control domains:

corecloudfileshare[.]xyz

attachmentsharingdrive[.]xyz

The malware can switch between the servers if communication with one fails. Both PowerShell components use token-authenticated communications, giving attackers redundant remote access to compromised machines.

TASK#STOMP also uses runtime-compiled C# code to disable TLS certificate validation, allowing communication even when the attacker's server uses an invalid or mismatched certificate.

Timestomping Used to Hide Malware

Another notable technique is timestomping.

TASK#STOMP modifies timestamps on several malicious files to make them appear older than they actually are. Researchers observed files being assigned a modification date of January 15, 2024.

Securonix cautions that this is an anti-forensic technique and does not indicate that the campaign has been active since January 2024.

What Security Teams Should Monitor

Defenders should investigate combinations of:

  • wscript.exe executing scripts from Desktop, Downloads, or Temp
  • Hidden PowerShell execution
  • PowerShell using -ExecutionPolicy Bypass
  • Unexpected scheduled-task creation
  • Scripts under %LOCALAPPDATA%\WinDefendSvc
  • Suspicious Startup-folder VBScript files
  • netsh commands requesting Wi-Fi keys
  • PowerShell spawning the C# compiler
  • Connections to the identified C2 domains
  • Multiple files sharing suspicious historical timestamps

Because TASK#STOMP establishes several persistence mechanisms, removing only one scheduled task or script may not fully eradicate the infection.

Security Takeaway

TASK#STOMP demonstrates how attackers can build capable surveillance malware primarily from tools already available on Windows.

Its combination of PowerShell, VBScript, redundant persistence, document monitoring, Wi-Fi credential theft, clipboard collection, screenshots, timestomping, and dual C2 infrastructure gives attackers persistent access while reducing reliance on conventional executable malware.

Securonix has not attributed TASK#STOMP to a known threat actor, and the victim organization, sector, initial access method, and overall scale of the campaign remain unknown.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.