[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f86g6aXkgHGZD8FOnG4z-WfJAcdfuFCTFUK7AhiCAp8Q":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":26,"created_at":27,"published_at":28,"article":29,"tags":33,"podcasts":52},"0a572504-2df1-4dd2-868d-8a7ead4074ce","taskstomp-backdoor-uses-scheduled-tasks-and-powershell-for-stealthy-document-theft","bf054632-275c-4277-ab48-ee71d3be6c1b","TASK#STOMP Backdoor Uses Scheduled Tasks and PowerShell for Stealthy Document Theft","TASK#STOMP exploits Windows scheduled tasks and PowerShell — two built-in, trusted system components — to establish persistent access and continuously exfiltrate sensitive business documents without triggering standard defenses. By compiling C# code at runtime, the malware evades signature-based detection, making traditional antivirus solutions insufficient. This attack highlights the danger of leaving PowerShell unrestricted and scheduled task creation unmonitored in enterprise environments. The continuous, automated nature of the document theft means that even a brief window of undetected access can result in significant data loss with long-term business consequences.","**Immediate actions:**\n- Audit and restrict PowerShell execution policies to only allow signed scripts via Group Policy or endpoint management tools.\n- Review all scheduled tasks across endpoints for unauthorized or suspicious entries and remove any that cannot be attributed to known software.\n- Enable PowerShell Script Block Logging and Module Logging to capture runtime-compiled code execution.\n\n**Detection measures:**\n- Deploy SIEM rules to alert on anomalous scheduled task creation, especially those spawning PowerShell or compiling code at runtime.\n- Monitor outbound data transfers for unusual volume or frequency patterns indicative of document exfiltration.\n- Implement Endpoint Detection and Response (EDR) solutions capable of detecting in-memory C# compilation and living-off-the-land techniques.\n\n**Long-term improvements:**\n- Apply the principle of least privilege to all user and service accounts to limit the blast radius of a compromised session.\n- Establish a Data Loss Prevention (DLP) policy to classify and restrict unauthorized transfer of sensitive business documents.\n- Conduct regular threat-hunting exercises focused on misuse of native Windows utilities such as PowerShell, Task Scheduler, and MSBuild.",[12,13,14,15,16,17,18,19,20,21,22,23,24,25],"CIS Control 4 – Secure Configuration of Enterprise Assets and Software","CIS Control 8 – Audit Log Management","CIS Control 13 – Network Monitoring and Defense","CIS Control 3 – Data Protection","NIST SP 800-53 AC-6 – Least Privilege","NIST SP 800-53 AU-12 – Audit Record Generation","NIST SP 800-53 SI-4 – System Monitoring","NIST SP 800-53 CM-7 – Least Functionality","NIST SP 800-53 SC-28 – Protection of Information at Rest","MITRE ATT&CK T1053.005 – Scheduled Task\u002FJob: Scheduled Task","MITRE ATT&CK T1059.001 – Command and Scripting Interpreter: PowerShell","MITRE ATT&CK T1027.004 – Obfuscated Files or Information: Compile After Delivery","GDPR Article 32 – Security of Processing","GDPR Article 33 – Notification of a Personal Data Breach","published","2026-09-22T12:22:08.087042+00:00","2026-09-22T12:22:08.004+00:00",{"id":7,"url":30,"slug":31,"title":32},"https:\u002F\u002Fhackread.com\u002Ftaskstomp-windows-backdoor-document-theft\u002F","new-task-stomp-windows-backdoor-enables-continuous-document-theft-b39d39","New TASK#STOMP Windows Backdoor Enables Continuous Document Theft",[34,40,46],{"id":35,"name":36,"slug":37,"description":38,"color":39},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":41,"name":42,"slug":43,"description":44,"color":45},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":47,"name":48,"slug":49,"description":50,"color":51},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]