Executive Summary
The TASK#STOMP campaign represents a sophisticated PowerShell-based backdoor operation that combines multiple persistence mechanisms with comprehensive data theft capabilities. Attackers use VBScript orchestrators to establish scheduled tasks with legitimate-sounding names like 'Local Credential Manager' and 'Windows Display Manager' to blend in with normal system operations. The malware automatically harvests business documents, Wi-Fi passwords, clipboard contents, takes screenshots, and maintains redundant command-and-control channels through dual PowerShell modules that monitor each other's execution status.
This incident highlights the growing trend of living-off-the-land attacks that abuse native Windows components to evade detection, representing a shift toward more subtle, persistent threats that prioritize long-term access over immediate disruption.
Why This Matters Now
Organizations face increasing threats from fileless malware that exploits legitimate system tools like PowerShell and Windows Script Host, making traditional signature-based detection ineffective and requiring enhanced behavioral monitoring and zero-trust security controls.
Attack Path Analysis
TASK#STOMP demonstrates a sophisticated multi-stage attack beginning with initial payload delivery via phishing or social engineering, followed by establishing multiple persistence mechanisms through scheduled tasks and startup folders. The malware then escalates privileges through PowerShell execution, maintains command and control via dual C2 channels, continuously exfiltrates sensitive documents and credentials, and implements cleanup procedures to evade detection while providing persistent remote access capabilities.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attacker delivered encoded VBScript file (95c9050t66.vbs) to victim's desktop, likely through email phishing or social engineering, using randomized filename to evade detection
MITRE ATT&CK® Techniques
Phishing
Visual Basic
Scheduled Task/Job
Registry Run Keys / Startup Folder
Timestomp
Data from Local System
Keychain
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – External and internal penetration testing
Control ID: Requirement 11.3.2
NYDFS 23 NYCRR 500 – Penetration testing and vulnerability assessments
Control ID: 500.15
DORA – Identification and classification of information and communication technology risk
Control ID: Article 8
CISA ZTMM 2.0 – Script execution controls
Control ID: Application Security
NIS2 Directive – Incident handling and response
Control ID: Article 21.2(a)
ISO 27001 – Controls against malware
Control ID: A.12.2.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
PowerShell backdoor targeting Iranian government tenders creates severe risks for document theft, credential harvesting, and unauthorized access to sensitive procurement data.
Financial Services
Document-stealing malware threatens financial institutions through Wi-Fi password theft, clipboard monitoring, and potential exfiltration of confidential client and transaction records.
Health Care / Life Sciences
Healthcare organizations face HIPAA compliance violations from automated document harvesting, screenshot capture, and real-time filesystem monitoring of patient records.
Legal Services
Law firms vulnerable to client confidentiality breaches through PowerShell backdoor's document theft capabilities, clipboard monitoring, and persistent surveillance mechanisms.
Sources
- TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Datahttps://thehackernews.com/2026/09/taskstomp-powershell-backdoor-steals.htmlVerified
- TASK#STOMP: PowerShell Backdoor Document Theft Remote Accesshttps://www.securonix.com/blog/task-stomp-powershell-backdoor-document-theft-remote-accessVerified
- CISA Alert on PowerShell-based Malware Campaignshttps://www.cisa.gov/news-events/cybersecurity-advisoriesVerified
- Microsoft Security Intelligence on PowerShell Securityhttps://www.microsoft.com/en-us/security/blog/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained TASK#STOMP's multi-stage attack by limiting lateral movement paths and reducing the attacker's blast radius across cloud workloads through microsegmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Microsegmentation policies would likely have limited the VBScript's ability to communicate with other workloads and restricted its access to cloud resources beyond the initially compromised endpoint.
Control: Zero Trust Segmentation
Mitigation: Identity-aware access controls would likely have constrained the malware's ability to escalate privileges across segmented workloads and limited its reach to unauthorized cloud resources and services.
Control: East-West Traffic Security
Mitigation: Microsegmentation enforcement would likely have blocked unauthorized inter-workload communication and constrained the malware's ability to establish redundant execution paths across cloud environments and connected systems.
Control: Multicloud Visibility & Control
Mitigation: Traffic visibility and control mechanisms would likely have detected and constrained unauthorized C2 communication patterns, reducing the attacker's ability to maintain persistent command channels across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely have restricted unauthorized data transmission paths and constrained the volume and frequency of sensitive data exfiltration from protected cloud environments.
Despite cleanup attempts, microsegmentation would likely have contained the overall blast radius and limited the scope of compromised assets to isolated network segments rather than enterprise-wide access.
Impact at a Glance
Affected Business Functions
- Document Management Systems
- Network Infrastructure Security
- Data Privacy and Compliance
- Information Technology Operations
Estimated downtime: 7 days
Estimated loss: $150,000
Business documents, Wi-Fi network credentials, clipboard contents containing potentially sensitive information, system metadata, screenshots of user activities, and authentication tokens. The malware performs continuous document collection and real-time file system monitoring, creating ongoing data exposure risks.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent PowerShell-based lateral movement between workloads and limit privilege escalation through identity-based policies
- • Deploy Egress Security & Policy Enforcement to block unauthorized data exfiltration to external domains like corecloudfileshare[.]xyz and attachmentsharingdrive[.]xyz
- • Enable Multicloud Visibility & Control to detect anomalous PowerShell execution patterns, suspicious automation, and dual C2 communication channels
- • Activate Threat Detection & Anomaly Response capabilities to baseline normal system behavior and alert on covert tools, remote access patterns, and file monitoring activities
- • Strengthen Cloud Firewall (ACF) with URL filtering and AI-driven traffic discovery to prevent initial payload delivery and block C2 communications to malicious domains



