The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files

The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files

Keypoints

  • TASK#STOMP searches for business documents and uploads them to attacker servers.
  • The malware steals saved Wi-Fi passwords, clipboard text, and screenshots.
  • It creates multiple persistence mechanisms, including scheduled tasks and a Startup folder copy.
  • Securonix found no clear attribution to a known threat actor or APT.
  • Defenders should hunt for the hardcoded token, malicious domains, hashes, and the malware’s scheduled tasks.

Read More: https://www.helpnetsecurity.com/2026/09/21/taskstomp-windows-backdoor/