TASK#STOMP Backdoor Steals Docs and Wi-Fi Keys - tech
(hx) 10:25 PM CEST - Sep,22 2026
- Post a comment / read (1) Securonix researchers disclosed TASK#STOMP on September 21, 2026, a Windows PowerShell backdoor built for long-term theft, not smash-and-grab damage. It hunts Word, PDF, PowerPoint, Excel, and archive files, then also grabs saved Wi-Fi passwords, clipboard text, and screenshots. The malware plants five persistence hooks—four scheduled tasks plus a Startup-folder copy - so deleting one copy may not clear the infection.
Securonix decoded two failover command servers and confirmed remote command execution, but it analyzed a single machine and did not name a threat group. How the first script lands on a desktop is still unconfirmed. There is no patch: this is abuse of built-in Windows tools, so defenders need to hunt the persistence and block the published C2 domains.
|