$ techbeacon▋
Malware

Researchers Uncover Windows Backdoor Leveraging PowerShell and Scheduled Tasks to Exfiltrate Documents

Researchers Uncover Windows Backdoor Leveraging PowerShell and Scheduled Tasks to Exfiltrate Documents

A newly identified Windows backdoor, dubbed TASK#STOMP, has been found to combine PowerShell scripts, scheduled tasks, and on‑the‑fly C# compilation to infiltrate corporate networks and siphon confidential files. Security analysts say the malware establishes a persistent foothold, allowing threat actors to retrieve documents long after initial infection.

The tool operates by creating scheduled tasks that trigger PowerShell commands at regular intervals. These commands dynamically compile C# code in memory, bypassing many traditional detection mechanisms that rely on static file signatures. Once compiled, the malicious component scans for business‑related documents and transmits them to remote servers under the attackers' control.

According to the initial report from Hackread, the backdoor’s architecture is designed for stealth. By using legitimate Windows utilities and avoiding the deployment of separate executable binaries, TASK#STOMP reduces its visibility to endpoint protection platforms that flag unknown files. The use of scheduled tasks also ensures the payload runs even after system reboots, maintaining continuous access.

Cybersecurity researchers note that the technique mirrors tactics employed by advanced persistent threat (APT) groups, which often blend legitimate administration tools with custom code to evade defenses. The reliance on PowerShell—a default component of modern Windows installations—means the malware can function on a wide range of systems without requiring additional software downloads.

Organizations are advised to review their PowerShell logging configurations, enforce strict execution policies, and monitor scheduled task creation for anomalies. Regular audits of outbound network traffic can also help detect unusual data transfers that may indicate document exfiltration.

While the full scope of the campaign remains under investigation, experts warn that the modular nature of TASK#STOMP could allow adversaries to adapt the backdoor for other malicious purposes, such as credential harvesting or lateral movement. Continued vigilance and timely patching of Windows components are essential to mitigate the risk posed by this emerging threat.

Source: Hackread
Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related