TASK#STOMP PowerShell Backdoor Steals Business Documents and Maintains Persistent Remote Access
A sophisticated PowerShell-based backdoor named TASK#STOMP has been discovered that specifically targets business documents while maintaining persistent remote access to compromised systems. The infection begins with VBScript execution, establishing persistence through scheduled tasks and startup folder entries. The malware deploys two primary PowerShell payloads that scan fixed drives for Word, PDF, PowerPoint, Excel, and archive files modified within the past year, excluding files larger than 500MB. It employs filesystem watchers for continuous collection of new documents. Additional capabilities include screenshot capture, Wi-Fi password theft, clipboard monitoring, and arbitrary command execution. The backdoor communicates with two command-and-control domains and uses compiled C helpers to bypass TLS certificate validation, enabling connections to servers with invalid certificates.
AI Analysis
Technical Summary
TASK#STOMP is a PowerShell backdoor that begins infection through VBScript execution and establishes persistence using scheduled tasks and startup folder entries. It deploys two main PowerShell payloads to scan fixed drives for business-related documents modified within the past year, excluding files over 500MB. The malware uses filesystem watchers for ongoing document collection. It also captures screenshots, steals Wi-Fi passwords, monitors clipboard data, and executes arbitrary commands. Communication with command-and-control servers occurs over domains 'corecloudfileshare.xyz' and 'attachmentsharingdrive.xyz'. The backdoor uses compiled C components to bypass TLS certificate validation, allowing connections to servers with invalid certificates. No CVE or known exploits in the wild are reported.
Potential Impact
The malware enables persistent remote access to compromised systems and exfiltrates sensitive business documents, potentially leading to data theft and espionage. Additional impacts include credential theft (Wi-Fi passwords), monitoring of clipboard data, and the ability to execute arbitrary commands, which could facilitate further compromise or lateral movement within a network.
Mitigation Recommendations
No official patch or remediation is indicated. Since this is malware, mitigation should focus on detection and removal using updated endpoint protection solutions and network monitoring for connections to the identified command-and-control domains. Restrict execution of unauthorized VBScript and PowerShell scripts, and monitor scheduled tasks and startup entries for suspicious activity. Validate TLS certificates on outbound connections to detect attempts to bypass certificate validation. Refer to vendor or security provider advisories for updated detection and removal tools.
Indicators of Compromise
- domain: corecloudfileshare.xyz
- domain: attachmentsharingdrive.xyz
TASK#STOMP PowerShell Backdoor Steals Business Documents and Maintains Persistent Remote Access
Description
A sophisticated PowerShell-based backdoor named TASK#STOMP has been discovered that specifically targets business documents while maintaining persistent remote access to compromised systems. The infection begins with VBScript execution, establishing persistence through scheduled tasks and startup folder entries. The malware deploys two primary PowerShell payloads that scan fixed drives for Word, PDF, PowerPoint, Excel, and archive files modified within the past year, excluding files larger than 500MB. It employs filesystem watchers for continuous collection of new documents. Additional capabilities include screenshot capture, Wi-Fi password theft, clipboard monitoring, and arbitrary command execution. The backdoor communicates with two command-and-control domains and uses compiled C helpers to bypass TLS certificate validation, enabling connections to servers with invalid certificates.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
TASK#STOMP is a PowerShell backdoor that begins infection through VBScript execution and establishes persistence using scheduled tasks and startup folder entries. It deploys two main PowerShell payloads to scan fixed drives for business-related documents modified within the past year, excluding files over 500MB. The malware uses filesystem watchers for ongoing document collection. It also captures screenshots, steals Wi-Fi passwords, monitors clipboard data, and executes arbitrary commands. Communication with command-and-control servers occurs over domains 'corecloudfileshare.xyz' and 'attachmentsharingdrive.xyz'. The backdoor uses compiled C components to bypass TLS certificate validation, allowing connections to servers with invalid certificates. No CVE or known exploits in the wild are reported.
Potential Impact
The malware enables persistent remote access to compromised systems and exfiltrates sensitive business documents, potentially leading to data theft and espionage. Additional impacts include credential theft (Wi-Fi passwords), monitoring of clipboard data, and the ability to execute arbitrary commands, which could facilitate further compromise or lateral movement within a network.
Defensive Guidance
No official patch or remediation is indicated. Since this is malware, mitigation should focus on detection and removal using updated endpoint protection solutions and network monitoring for connections to the identified command-and-control domains. Restrict execution of unauthorized VBScript and PowerShell scripts, and monitor scheduled tasks and startup entries for suspicious activity. Validate TLS certificates on outbound connections to detect attempts to bypass certificate validation. Refer to vendor or security provider advisories for updated detection and removal tools.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://cyberpress.org/taskstomp-backdoor-steals-documents/?amp=1"]
- Pulse Id
- 6ab51a6bd938b813a0c50c5c
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaincorecloudfileshare.xyz | — | |
domainattachmentsharingdrive.xyz | — |
Threat ID: 6ab57aedf7a7c54106bff429
Added to database: 09/24/2026, 19:33:01 UTC
Last enriched: 09/24/2026, 19:48:28 UTC
Last updated: 09/25/2026, 02:05:49 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.