TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
TASK#STOMP is a new PowerShell backdoor that steals business documents, Wi-Fi passwords and clipboard data while using scheduled tasks and dual C2 servers for persistent access.

Cybersecurity researchers have uncovered a new Windows malware campaign dubbed TASK#STOMP, which deploys a PowerShell-based backdoor capable of continuously stealing business documents, saved Wi-Fi passwords, clipboard contents, screenshots, and other sensitive information.
Researchers at Securonix say the malware relies heavily on legitimate Windows components, including VBScript, PowerShell, Task Scheduler, and netsh, helping malicious activity blend with normal system operations.
How TASK#STOMP Works
The observed infection begins when wscript.exe executes an encoded VBScript file placed on the victim's desktop.
The exact initial delivery method remains unknown. Researchers say phishing or social engineering is possible, but this has not been confirmed.
The attack chain follows:
Malicious VBScript → Scheduled Tasks → PowerShell Loaders → Backdoor Execution → Data Theft → Dual C2 Communication
The malware creates multiple scheduled tasks with legitimate-looking names such as:
Local Credential ManagerNetwork Audio ServiceWindows Display ManagerDevice Credential Handler
It also places msdiag.vbs inside the Windows Startup folder, providing an additional persistence mechanism whenever the user logs in.
Two PowerShell Backdoor Components
TASK#STOMP launches two primary PowerShell components:
| Component | Purpose |
|---|---|
sys_loader.ps1 |
Loads the main surveillance and data-stealing payload |
win_conn.ps1 |
Maintains a secondary C2 and remote-command channel |
The components decode payloads stored inside diag_pack.dat and win_conn_cfg.dat.
They are also designed to monitor one another and attempt to restore functionality if one component stops, providing additional resilience.
What Can TASK#STOMP Steal?
Once active, the backdoor can:
- Search for and exfiltrate Word, PDF, PowerPoint, Excel and archive files
- Monitor the filesystem for newly created or modified documents
- Extract saved Wi-Fi passwords
- Capture clipboard contents
- Take screenshots
- Collect system information
- Execute arbitrary PowerShell commands
- Download and execute additional attacker instructions
The malware uses commands such as netsh wlan show profile ... key=clear to retrieve accessible saved Wi-Fi credentials.
This makes TASK#STOMP particularly concerning for corporate environments because it is designed for continuous collection, rather than simply stealing files once and exiting.
Dual C2 Infrastructure
Researchers identified two command-and-control domains:
corecloudfileshare[.]xyz
attachmentsharingdrive[.]xyz
The malware can switch between the servers if communication with one fails. Both PowerShell components use token-authenticated communications, giving attackers redundant remote access to compromised machines.
TASK#STOMP also uses runtime-compiled C# code to disable TLS certificate validation, allowing communication even when the attacker's server uses an invalid or mismatched certificate.
Timestomping Used to Hide Malware
Another notable technique is timestomping.
TASK#STOMP modifies timestamps on several malicious files to make them appear older than they actually are. Researchers observed files being assigned a modification date of January 15, 2024.
Securonix cautions that this is an anti-forensic technique and does not indicate that the campaign has been active since January 2024.
What Security Teams Should Monitor
Defenders should investigate combinations of:
wscript.exeexecuting scripts from Desktop, Downloads, or Temp- Hidden PowerShell execution
- PowerShell using
-ExecutionPolicy Bypass - Unexpected scheduled-task creation
- Scripts under
%LOCALAPPDATA%\WinDefendSvc - Suspicious Startup-folder VBScript files
netshcommands requesting Wi-Fi keys- PowerShell spawning the C# compiler
- Connections to the identified C2 domains
- Multiple files sharing suspicious historical timestamps
Because TASK#STOMP establishes several persistence mechanisms, removing only one scheduled task or script may not fully eradicate the infection.
Security Takeaway
TASK#STOMP demonstrates how attackers can build capable surveillance malware primarily from tools already available on Windows.
Its combination of PowerShell, VBScript, redundant persistence, document monitoring, Wi-Fi credential theft, clipboard collection, screenshots, timestomping, and dual C2 infrastructure gives attackers persistent access while reducing reliance on conventional executable malware.
Securonix has not attributed TASK#STOMP to a known threat actor, and the victim organization, sector, initial access method, and overall scale of the campaign remain unknown.
Related reporting
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT Malware via ClickFix
Attackers abuse ChatGPT Custom GPTs and sponsored Google results to redirect victims to ClickFix pages that execute PowerShell and install remote access trojan malware.
Star Blizzard Targets 100+ Organizations With Fake Event Invites and CosmicPulse Backdoor
Russia-linked Star Blizzard targets more than 100 organizations using fake event invitations, the new RedFlick malware delivery technique and the CosmicPulse Windows backdoor.
101 Malicious npm Packages Secretly Add Developers to WhatsApp Groups
Researchers uncover 101 malicious npm packages in the PhantomSub campaign that abuse authenticated WhatsApp sessions to secretly add developers to attacker-controlled groups and channels.


