research
Published 2026-09-21
Verified 2026-09-22

Securonix: TASK#STOMP PowerShell backdoor — VBS/schtasks timestomp, document theft + dual C2

Securonix Threat Research (Akshay Gaikwad, Aaron Beardslee; published 21 September 2026) details TASK#STOMP, a script-driven Windows backdoor that begins with a randomly named desktop VBScript executed via wscript.exe and stages under %LOCALAPPDATA%\WinDefendSvc. Persistence: four schtasks XML registrations with rotating OS-like names (e.g. Local Credential Manager / Network Audio Service) plus Startup-folder msdiag.vbs; fixed-date timestomp (2024-01-15 08:30:00) on core artifacts; dual hidden PowerShell branches (sys_loader.ps1 / win_conn.ps1) that mutually watchdog and compile C# helpers at runtime via csc.exe (TLS validation disabled). Payload: automated business-document harvest and live filesystem watch, Wi-Fi password and clipboard theft, screenshots, and arbitrary remote commands over two token-authenticated C2 hosts (corecloudfileshare[.]xyz / attachmentsharingdrive[.]xyz) with failover. Initial access path not confirmed (phishing/social engineering suspected). Orchestrator also opens an IranTenders Chrome page and runs purge.bat cleanup. Amplify: The Hacker News 21 September 2026. No CVE.

Product
Windows endpoints (WSH / PowerShell / Task Scheduler / .NET csc)
Versions
n/a (malware framework; living-off-the-land Windows utilities)
Exploited in Australia?
unknown
Patch to
Hunt schtasks creates with WinDefendSvc XML paths and OS-camouflage task names; enable PowerShell Script Block Logging / AMSI; alert on hidden powershell spawning csc.exe/cvtres.exe; block/monitor corecloudfileshare[.]xyz and attachmentsharingdrive[.]xyz; recover Zone.Identifier and email/browser telemetry for the initial VBS.

Primary: Securonix — TASK#STOMP PowerShell backdoor (21 Sep 2026) · Vendor: Securonix Threat Research primary analysis · The Hacker News — TASK#STOMP amplify (21 Sep 2026)

tech identity