Researchers Discovered New Windows Backdoor Malware
The TASK#STOMP malware targets corporate document espionage through persistent Windows task manipulation.
Updated on Sept. 21, 2026 in Cybersecurity

Live Poll
Do you trust your organization's current security measures to stop new, unknown malware threats?
Security researchers identified a new Windows-based backdoor named TASK#STOMP designed to exfiltrate business documents and sensitive credentials. The malware achieves persistence through multiple Windows system footholds and uses anti-forensic techniques to evade detection.
Why it matters
By prioritizing the theft of Word, PDF, PowerPoint, and Excel files, the malware appears engineered for corporate espionage. The tactics suggest a targeted campaign against entities managing trade contracts, particularly those with an Iran-related nexus.
The malware establishes persistence via 4 scheduled tasks and a copy in the Windows Startup folder. It uses hardcoded authentication tokens that remain constant across all victim machines.
The players
Securonix
A security analytics firm providing threat detection and investigation capabilities for enterprise environments.
Windows
The Microsoft-developed operating system targeted by TASK#STOMP for document and credential exfiltration.
The details
The infection begins with the execution of a VBScript file on the user's desktop, which then deploys two PowerShell modules that monitor each other to ensure continuity. To remain hidden, the malware masks its files within a folder named WinDefendSvc and utilizes anti-forensic measures to backdate its file timestamps to January 15, 2024. Communication and theft are facilitated by hidden PowerShell scripts that specifically target corporate file formats.
Timeline
January 15, 2024: Fabricated timestamp applied to malware files.
September 21, 2026: Official publication of the Securonix research report.
The Tech Race
This discovery follows the firm's ongoing analysis of persistent backdoors targeting industrial and trade-focused organizations. It highlights a shift toward increasingly sophisticated anti-forensic tactics in targeted corporate espionage.
Organizations should monitor for suspicious PowerShell activity and ensure that unauthorized scheduled tasks are audited within their Windows environments. There is currently no publicly available patch or indicator-of-compromise list for end-users to apply against this specific threat.
The takeaway
The use of hardcoded authentication tokens suggests this malware may be quickly identifiable by network defenders scanning for static traffic patterns. Security teams should monitor for the WinDefendSvc folder and any unusual VBScript execution paths to mitigate risk.
Further reading
For more on evolving threat vectors and corporate espionage, see Cybersecurity.
Live Poll
Do you trust your organization's current security measures to stop new, unknown malware threats?






