New TASK#STOMP Windows Backdoor Enables Continuous Document Theft

https://hackread.com/wp-content/uploads/2026/09/taskstomp-windows-backdoor-document-theft-2.jpg

Securonix researchers have detailed a new Windows backdoor campaign tracked as TASK#STOMP, which was discovered on a compromised Windows system stealing business documents and maintaining remote access.

The research, shared with Hackread.com, found that the malware uses Windows Script Host, PowerShell and Task Scheduler to set up several ways to keep running on the machine.

Multiple Ways to Stay on an Infected System

The attack begins with a VBScript installer that creates a folder named WinDefendSvc (that resembles a legitimate Windows service) under the user’s LocalAppData directory. The script then creates four scheduled tasks using system-like names and places another script in the Windows Startup folder.

This provides redundant persistence through four scheduled tasks and a Startup-folder script, allowing the malware to run again after the user logs in. If one method is removed, the other can help restore the infection.

Moreover, the malware performs timestomping(changing file timestamps...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more