Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-22 · updated: 2026-09-22 · tags: [incident, global, phishing] · confidence: high · severity: critical · affected_sectors: [global] · au_impact: true

Securonix researchers have detailed a campaign they call TASK#STOMP that delivers a PowerShell backdoor capable of "automatically harvesting and exfiltrating business documents, watching the filesystem for new files in real time", stealing Wi-Fi passwords and clipboard contents, capturing screenshots and accepting arbitrary remote commands through two redundant, token-authenticated command-and-control servers. The chain begins with wscript.exe executing an encoded VBScript staged on the victim's desktop under a random filename, 95c9050t66.vbs; the initial access path is unclear and may have been email-based phishing. The script establishes persistence through scheduled tasks deliberately named Local Credential Manager, Network Audio Service, Windows Display Manager and Device Credential Handler so they blend into normal operating-system activity, and adds a backup persistence route through the Startup folder script msdiag.vbs. Two further modules run as separate processes — sys_loader.ps1, decoding diag_pack.dat, and win_conn.ps1, decoding win_conn_cfg.dat — communicating with infrastructure at corecloudfileshare[.]xyz or attachmentsharingdrive[.]xyz. The pair hold a mutual-watchdog relationship, each restarting the other if it stops, so terminating one branch does not end the intrusion. Timestomping and cleanup routines are present to frustrate casual administrative review and forensic analysis.

Attribute Detail
Sector Global (Macro)
Date 2026-09-22
Source The Hacker News
Reliability Tier 2