EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

Editorial source
Editorial OSINT source. The content is an indication to verify with independent institutional or technical sources before operational decisions.
EudorIA operational summary

What it means

Priority 70/100

TASK#STOMP è una campagna di attacco che utilizza un backdoor PowerShell per rubare dati sensibili. L'attacco inizia con un file VBScript, che si avvia tramite wscript.exe e si basa su persistence tramite task pianificati. Il backdoor comunica con due C2 server e raccoglie documenti, password Wi-Fi, contenuti del clipboard e screenshot. La sua struttura riduce la visibilità e complica l'analisi forense.

Why it matters

Per le PMI italiane, TASK#STOMP rappresenta un rischio significativo per la sicurezza dei dati sensibili e la privacy. L'attacco può compromettere informazioni aziendali critiche e danneggiare la reputazione. La mancanza di rilevamento e la complessità del malware rendono necessario un intervento rapido e mirato.

Potential operational benefits

  • Riduzione della superficie esposta e del rischio di attacchi
  • Miglioramento della rilevazione e risposta agli eventi anomali
  • Aumento della protezione delle credenziali e dei dati sensibili
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsFirewall NGFW / IPSMFA / IdentitàEDR / XDRPatch managementSegmentazione di rete
AudienceITSOCCISO
Information centre

Translation in progress

The Hacker News

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts. The backdoor "automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary

Source
The Hacker News
Publishing entity
The Hacker News
Entity type
editorial osint
Area
Global
Original language
en · translation in preparation
Publication
21/09/2026 16:15
MITRE ATT&CK
T1078, T1486, T1053, T1071
Open the original source