← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 22, 2026 · 13:45via Cyber Security News

New TASK#STOMP Backdoor Uses PowerShell to Steal Documents and Wi-Fi Passwords

Brief

TASK#STOMP is a newly analyzed Windows backdoor that turns ordinary built-in tools into a durable spying operation.

It uses a Visual Basic Script installer, hidden PowerShell, scheduled tasks, and runtime code compilation to collect business documents, saved Wi-Fi passwords, clipboard data, and screenshots from compromised machines.

The observed infection begins with a randomly named VBS file in a user-accessible location. Its delivery route remains unconfirmed: the available evidence cannot distinguish phishing, a browser download, removable media, remote access, or an extracted archive. Once launched, the script builds several ways to survive a restart or partial cleanup.

Securonix said in a report shared with Cyber Security News (CSN) that its analysts decoded the final payloads and identified TASK#STOMP as a fully working PowerShell backdoor.

Read more on Cyber Security News