← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 22, 2026 · 08:29via CyberPress

TASK#STOMP PowerShell Implant Uses Dual C2 Servers for Document Theft and Remote Commands

Brief

Researchers have uncovered TASK#STOMP, a PowerShell-based backdoor that steals business documents, collects Wi-Fi passwords and clipboard data, captures screenshots, and executes attacker commands.

The malware uses two command-and-control (C2) servers with automatic failover, helping operators retain access if one server becomes unavailable.

The attack begins with a malicious Visual Basic Script (VBS) file launched through Windows Script Host. The script creates four scheduled tasks using XML files stored in the user’s LocalAppData directory.

It also places a copy of itself, named msdiag.vbs , in the Windows Startup folder to regain execution whenever the victim signs in.

Read more on CyberPress→