Skip to main content

TASK#STOMP PowerShell Backdoor Steals Business Documents and Maintains Persistent Remote Access

0
Medium
Published: 09/24/2026 (09/24/2026, 12:41:15 UTC)
Source: AlienVault OTX General

Description

A sophisticated PowerShell-based backdoor named TASK#STOMP has been discovered that specifically targets business documents while maintaining persistent remote access to compromised systems. The infection begins with VBScript execution, establishing persistence through scheduled tasks and startup folder entries. The malware deploys two primary PowerShell payloads that scan fixed drives for Word, PDF, PowerPoint, Excel, and archive files modified within the past year, excluding files larger than 500MB. It employs filesystem watchers for continuous collection of new documents. Additional capabilities include screenshot capture, Wi-Fi password theft, clipboard monitoring, and arbitrary command execution. The backdoor communicates with two command-and-control domains and uses compiled C helpers to bypass TLS certificate validation, enabling connections to servers with invalid certificates.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/24/2026, 19:48:28 UTC

Technical Analysis

TASK#STOMP is a PowerShell backdoor that begins infection through VBScript execution and establishes persistence using scheduled tasks and startup folder entries. It deploys two main PowerShell payloads to scan fixed drives for business-related documents modified within the past year, excluding files over 500MB. The malware uses filesystem watchers for ongoing document collection. It also captures screenshots, steals Wi-Fi passwords, monitors clipboard data, and executes arbitrary commands. Communication with command-and-control servers occurs over domains 'corecloudfileshare.xyz' and 'attachmentsharingdrive.xyz'. The backdoor uses compiled C components to bypass TLS certificate validation, allowing connections to servers with invalid certificates. No CVE or known exploits in the wild are reported.

Potential Impact

The malware enables persistent remote access to compromised systems and exfiltrates sensitive business documents, potentially leading to data theft and espionage. Additional impacts include credential theft (Wi-Fi passwords), monitoring of clipboard data, and the ability to execute arbitrary commands, which could facilitate further compromise or lateral movement within a network.

Defensive Guidance

No official patch or remediation is indicated. Since this is malware, mitigation should focus on detection and removal using updated endpoint protection solutions and network monitoring for connections to the identified command-and-control domains. Restrict execution of unauthorized VBScript and PowerShell scripts, and monitor scheduled tasks and startup entries for suspicious activity. Validate TLS certificates on outbound connections to detect attempts to bypass certificate validation. Refer to vendor or security provider advisories for updated detection and removal tools.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://cyberpress.org/taskstomp-backdoor-steals-documents/?amp=1"]
Pulse Id
6ab51a6bd938b813a0c50c5c

Indicators of Compromise

Domain

ValueDescriptionCopy
domaincorecloudfileshare.xyz
—
domainattachmentsharingdrive.xyz
—

Threat ID: 6ab57aedf7a7c54106bff429

Added to database: 09/24/2026, 19:33:01 UTC

Last enriched: 09/24/2026, 19:48:28 UTC

Last updated: 09/25/2026, 02:05:49 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses