Researchers Discovered New Windows Backdoor Malware

The TASK#STOMP malware targets corporate document espionage through persistent Windows task manipulation.

Updated on Sept. 21, 2026 in Cybersecurity

Bold flat-color editorial illustration showing stylized interlocking metallic lock parts on an office hinge, symbolizing digital security.
Security researchers identified a new Windows-based backdoor called TASK#STOMP, which targets corporate documents and sensitive credentials for potential espionage. AI Illustration. Upload story photo >

Live Poll

Do you trust your organization's current security measures to stop new, unknown malware threats?

Security researchers identified a new Windows-based backdoor named TASK#STOMP designed to exfiltrate business documents and sensitive credentials. The malware achieves persistence through multiple Windows system footholds and uses anti-forensic techniques to evade detection.

Why it matters

By prioritizing the theft of Word, PDF, PowerPoint, and Excel files, the malware appears engineered for corporate espionage. The tactics suggest a targeted campaign against entities managing trade contracts, particularly those with an Iran-related nexus.

The malware establishes persistence via 4 scheduled tasks and a copy in the Windows Startup folder. It uses hardcoded authentication tokens that remain constant across all victim machines.

The players

Securonix

A security analytics firm providing threat detection and investigation capabilities for enterprise environments.

Windows

The Microsoft-developed operating system targeted by TASK#STOMP for document and credential exfiltration.

The details

The infection begins with the execution of a VBScript file on the user's desktop, which then deploys two PowerShell modules that monitor each other to ensure continuity. To remain hidden, the malware masks its files within a folder named WinDefendSvc and utilizes anti-forensic measures to backdate its file timestamps to January 15, 2024. Communication and theft are facilitated by hidden PowerShell scripts that specifically target corporate file formats.

Timeline

  1. January 15, 2024: Fabricated timestamp applied to malware files.

  2. September 21, 2026: Official publication of the Securonix research report.

The Tech Race

This discovery follows the firm's ongoing analysis of persistent backdoors targeting industrial and trade-focused organizations. It highlights a shift toward increasingly sophisticated anti-forensic tactics in targeted corporate espionage.

Organizations should monitor for suspicious PowerShell activity and ensure that unauthorized scheduled tasks are audited within their Windows environments. There is currently no publicly available patch or indicator-of-compromise list for end-users to apply against this specific threat.

The takeaway

The use of hardcoded authentication tokens suggests this malware may be quickly identifiable by network defenders scanning for static traffic patterns. Security teams should monitor for the WinDefendSvc folder and any unusual VBScript execution paths to mitigate risk.

Further reading

For more on evolving threat vectors and corporate espionage, see Cybersecurity.

Live Poll

Do you trust your organization's current security measures to stop new, unknown malware threats?