Find notable cyber news and cases, enriched with sources, timelines, and signals.

TASK#STOMP PowerShell backdoor with redundant C2

Malware Activity
First reported
Last updated
Happening score
H score 27
1 unique sources, 1 articles

Summary

Hide ▲

The TASK#STOMP PowerShell backdoor is stealing business documents, Wi‑Fi passwords, clipboard contents, and screenshots from compromised hosts while retaining remote command execution. It uses two redundant, token-authenticated C2 servers and multiple persistence layers to keep operating after one path is removed. The activity raises the risk of ongoing credential theft and long-lived access on infected Windows systems.

Related Happenings

TASK#STOMP PowerShell backdoor delivery campaign

Campaign
H score31 First: 21.09.2026 17:15 Last: 21.09.2026 17:15 Sources 1

How related: Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts.

About this happening: TASK#STOMP is a newly disclosed campaign that uses VBScript and PowerShell stages to deploy a backdoor on compromised hosts, creating ongoing risk of data thef...

TerminalFix fake Cloudflare CAPTCHA reverse-tunnel campaign

Campaign
H score37 First: 30.08.2026 10:36 Last: 30.08.2026 10:36 Sources 1

About this happening: The TerminalFix campaign is using fake Cloudflare CAPTCHA pages on compromised websites to trick users into running malicious PowerShell commands, expanding risk a...

ACR Stealer browser credential and document theft activity

Malware Activity
H score29 First: 17.07.2026 11:56 Last: 17.07.2026 11:56 Sources 1

About this happening: ACR Stealer activity has expanded across enterprise environments, with Microsoft linking the malware to late April to mid-June 2026 campaigns that use ClickFix lur...

Windows cryptocurrency clipper campaign targeting users via USB LNK worms

Campaign
H score32 First: 18.06.2026 17:30 Last: 18.06.2026 17:30 Sources 1

About this happening: A Windows cryptocurrency clipper campaign is actively targeting users since February 2026, putting clipboard data, wallet addresses, and seed phrases at risk. The operatio...

Malicious LNK GitHub C2 campaign targeting South Korea

Campaign
H score29 First: 02.04.2026 16:00 Last: 02.04.2026 16:00 Sources 1

About this happening: A malicious LNK-file campaign targeting users in South Korea is using GitHub as C2 to support persistent access on Windows systems. The operation relies on Power...

Timeline

  1. 21.09.2026 17:15 2 articles · 7h ago

    TASK#STOMP delivers a PowerShell backdoor that steals documents and credentials

    Initial Disclosure

    Securonix disclosed TASK#STOMP, a PowerShell backdoor campaign that begins when wscript.exe executes the encoded VBScript 95c9050t66.vbs from a victim's desktop, uses scheduled tasks and a Startup-folder launcher to persist as Local Credential Manager, Network Audio Service, Windows Display Manager, and Device Credential Handler, then runs hidden PowerShell modules such as sys_loader.ps1 and win_conn.ps1 to decode diag_pack.dat and win_conn_cfg.dat, maintain redundant token-authenticated C2 on corecloudfileshare[.]xyz and attachmentsharingdrive[.]xyz, and steal system metadata, business documents, Wi-Fi passwords, clipboard contents, screenshots, and arbitrary command execution; the chain also opens Chrome to irantenders[.]com and may run purge.bat to remove traces.

    Show sources