Researchers describe TASK#STOMP, a Windows PowerShell backdoor used in a malicious campaign that compromises hosts to collect sensitive information. According to analysis shared by Securonix Threat Research, the malware searches infected drives for business documents and uploads them to attacker-controlled servers. It also continues running after initial access, watching for new or changed files and then exfiltrating those as they appear.
Multiple outlets report that TASK#STOMP additionally targets credential and user-data sources. It steals saved Wi‑Fi passwords, captures clipboard contents, and takes screenshots. The backdoor also responds to commands sent by its operators, allowing further actions beyond data theft.
The reporting focuses on the technical capabilities of the malware based on Securonix’s reverse engineering and investigation. Securonix notes its findings are derived from analysis of a single infected machine, limiting conclusions about how widely the malware has been deployed or how many organizations are affected. Other coverage largely reiterates the same feature set and behavior—document harvesting, real-time file monitoring, Wi‑Fi and clipboard theft, and screenshot capture—without adding different estimates of scope.