New TASK#STOMP Backdoor Uses PowerShell to Steal Documents and Wi-Fi Passwords
Brief
TASK#STOMP is a newly analyzed Windows backdoor that turns ordinary built-in tools into a durable spying operation.
It uses a Visual Basic Script installer, hidden PowerShell, scheduled tasks, and runtime code compilation to collect business documents, saved Wi-Fi passwords, clipboard data, and screenshots from compromised machines.
The observed infection begins with a randomly named VBS file in a user-accessible location. Its delivery route remains unconfirmed: the available evidence cannot distinguish phishing, a browser download, removable media, remote access, or an extracted archive. Once launched, the script builds several ways to survive a restart or partial cleanup.
Securonix said in a report shared with Cyber Security News (CSN) that its analysts decoded the final payloads and identified TASK#STOMP as a fully working PowerShell backdoor.
