Find notable cyber news and cases, enriched with sources, timelines, and signals.

TASK#STOMP PowerShell backdoor delivery campaign

Campaign
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

TASK#STOMP is a newly disclosed campaign that uses VBScript and PowerShell stages to deploy a backdoor on compromised hosts, creating ongoing risk of data theft and remote command execution. The payload steals business documents, Wi‑Fi passwords, clipboard contents, and screenshots, then sends them through redundant C2 servers. The chain relies on wscript.exe, scheduled tasks, and Startup-folder persistence to stay resident and hard to remove.

Related Happenings

TASK#STOMP PowerShell backdoor with redundant C2

Malware Activity
H score27 First: 21.09.2026 17:15 Last: 21.09.2026 17:15 Sources 1

How related: The backdoor "automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary remote commands through two redundant, token-authenticated C2 servers,"

About this happening: The TASK#STOMP PowerShell backdoor is stealing business documents, Wi‑Fi passwords, clipboard contents, and screenshots from compromised hosts while retain...

ACR Stealer browser credential and document theft activity

Malware Activity
H score29 First: 17.07.2026 11:56 Last: 17.07.2026 11:56 Sources 1

About this happening: ACR Stealer activity has expanded across enterprise environments, with Microsoft linking the malware to late April to mid-June 2026 campaigns that use ClickFix lur...

Veil#Drop PureLog Stealer in-memory delivery operation

Malware Activity
H score30 First: 01.07.2026 17:30 Last: 01.07.2026 17:30 Sources 1

About this happening: Veil#Drop is delivering PureLog Stealer through a fileless chain that keeps payloads entirely in memory, reducing disk artifacts and raising the chance of evading...

WhatsApp VBScript infection chain installing ManageEngine RMM Central

Malware Activity
H score20 First: 23.06.2026 08:38 Last: 23.06.2026 08:38 Sources 1

About this happening: VBScript attachments spread through WhatsApp direct messages are now driving a multi-stage Windows infection chain that can end in remote access to victim systems. The...

PureLogs infostealer purchase-order phishing delivery chain

Malware Activity
H score21 First: 27.05.2026 11:00 Last: 27.05.2026 11:00 Sources 1

About this happening: The PureLogs infostealer is being delivered through purchase-order-themed phishing emails, creating a Windows infection chain that steals browser credentials, Di...

Timeline

  1. 21.09.2026 17:15 2 articles · 7h ago

    TASK#STOMP uses VBScript and PowerShell to steal data from compromised hosts

    Initial Disclosure

    TASK#STOMP is a PowerShell backdoor campaign that begins with wscript.exe executing an encoded VBScript file staged as 95c9050t66.vbs on a victim desktop. The VBScript establishes persistence with scheduled tasks named Local Credential Manager, Network Audio Service, Windows Display Manager, and Device Credential Handler, adds a Startup-folder launcher through msdiag.vbs, and starts hidden PowerShell modules that steal system metadata, business documents, Wi-Fi passwords, clipboard contents, and screenshots while maintaining redundant C2 on corecloudfileshare[.]xyz and attachmentsharingdrive[.]xyz. The chain also uses mutual watchdog logic, timestomping, cleanup behavior, and a final Chrome visit to irantenders[.]com.

    Show sources