
TASK#STOMP Deploys Dual PowerShell Modules with Mutual Watchdog and Timestomping
TASK#STOMP uses layered VBScript and PowerShell persistence with dual C2 channels and data-harvesting modules. The campaign shows deliberate anti-forensic techniques and a possible Iran-related final action. Evidence points to espionage tradecraft rather than commodity malware.
The infection begins with wscript.exe executing a randomly named VBScript on the desktop that creates persistence through scheduled tasks titled Local Credential Manager, Network Audio Service, Windows Display Manager, and Device Credential Handler plus a backup msdiag.vbs in the startup folder. It then launches hidden PowerShell processes that terminate duplicates, apply timestomping, and decode diag_pack.dat and win_conn_cfg.dat to activate document exfiltration, filesystem monitoring, screenshot capture, and arbitrary command execution.
Securonix reporting shows the two PowerShell modules maintain a mutual-watchdog relationship while sharing the same token-authenticated C2 servers. The final observed actions include opening irantenders[.]com and running an unrecovered purge.bat script. These steps indicate deliberate operational security to evade both automated detection and manual forensic review.
The campaign fits patterns seen in prior espionage tools that combine redundant persistence with minimal external dependencies, though initial access remains unconfirmed beyond possible phishing. The Iranian tender site connection suggests targeting or staging related to government procurement data rather than generic crimeware.
Next indicators to monitor include new variants reusing the same task names or C2 infrastructure and any overlap with documented Iranian infrastructure campaigns tracked by commercial threat intel platforms.
Mandiant: New TASK#STOMP samples sharing the four scheduled task names appear in public repositories within 45 days
Sources (2)
- [1]Primary Source(https://thehackernews.com/2026/09/taskstomp-powershell-backdoor-steals.html)
- [2]Supporting Source(https://www.securonix.com/blog/taskstomp-powershell-backdoor-analysis/)