HomeIntelligenceBrief
BREACH BRIEF 🟠 High ThreatIntel

TASK#STOMP Windows Backdoor Enables Continuous Document Theft via PowerShell and Scheduled Tasks

Researchers discovered TASK#STOMP, a Windows backdoor that employs PowerShell, scheduled‑task abuse, and runtime C# compilation to exfiltrate business documents and maintain persistence. The technique underscores the importance of continuous monitoring of privileged task creation and PowerShell activity for audit readiness.

Verisq™ Intelligence · 📅 September 22, 2026 · 📰 hackread.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
hackread.com

TASK#STOMP Windows Backdoor Enables Continuous Document Theft via PowerShell and Scheduled Tasks

What Happened — Researchers identified a new Windows backdoor, dubbed TASK#STOMP, that leverages PowerShell, scheduled‑task abuse, and runtime C# compilation to silently harvest business documents and retain persistent remote access.

Why It Matters for Trust & Control Assurance

  • Continuous creation of unauthorized scheduled tasks bypasses typical change‑management controls, highlighting the need for real‑time task‑creation monitoring.
  • PowerShell script‑block logging and execution‑policy enforcement are essential evidence sources for an audit‑ready control‑assurance program.
  • Detecting and evidencing such backdoor activity supports the access‑control objective that underpins many frameworks (NIST CSF, ISO 27001, etc.).

Who Is Affected – Any organization that runs Windows workstations or servers, especially those handling sensitive business documents (finance, legal, healthcare, SaaS providers).

Recommended Actions – Enable comprehensive PowerShell logging, enforce least‑privilege for scheduled‑task creation, deploy endpoint detection and response (EDR) with scheduled‑task telemetry, and regularly review audit logs for anomalous code execution. Source: HackRead

Technical Notes — The backdoor compiles C# code at runtime, executes via PowerShell, and registers a scheduled task for persistence. No CVE is associated; the technique exploits legitimate Windows features. Source: HackRead

📰 Original Source
https://hackread.com/taskstomp-windows-backdoor-document-theft/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →