Skip to content

Security1 publisher2 min readPublished

TASK#STOMP backdoor keeps copying each new or edited document after its first sweep

TASK#STOMP, a Windows backdoor researchers dissected, uploads a victim's business documents and then stays to copy each new or edited one. Loss from a single infection keeps growing until someone finds and removes it.

The Watch · Security desk

Illustration accompanying TASK#STOMP backdoor keeps copying each new or edited document after its first sweep

What happened

  • TASK#STOMP also steals saved Wi-Fi passwords and clipboard text, takes screenshots, and runs any command its operators send.
  • Check Point shipped emergency fixes for CVE-2026-93616 in its Management Server, a flaw exploited as far back as July 23, 2026.
  • GreyNoise reported that a Chinese-speaking actor used CVE-2026-7273 to pull data from 996 unpatched Zyxel GS1900 switches in 48 countries.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Wi-Fi passwords taken from an infected laptop stay valid after the laptop is reimaged, so the wireless network remains reachable to the operators until its keys are changed.
  • decision Applying the CVE-2026-93616 fix does not remove access gained in the weeks of exploitation before it, so Management Server owners have to hunt for prior compromise as well as patch.
  • constraint Until Gyazo publishes which data fields were exposed, account holders cannot tell whether the breach calls for a password change or any action at all.

TASK#STOMP starts by searching a victim's drives for business documents and uploading them to attacker servers [1]. It then stays on the machine and takes each new or edited document as it appears [1]. So a responder sizing the loss has to count two sets. One is every document on disk at infection. The other is every document written or changed between infection and removal [3].

Even that inventory undercounts what left the host. Clipboard capture and screenshots pick up material that never gets saved as a document [2].

Help Net Security's weekly roundup describes what the backdoor can do. It does not name the researchers, the delivery method, an operator or a victim count. The Gyazo breach appears in its headline without a list of the data taken [1][4].

Ranked by how exploitable they are, the week's items with deadlines are on network edge gear. On September 9, Check Point patched CVE-2026-85102, a remote code execution flaw in its Quantum Security Gateway that works before authentication. Probing began a few days later [6]. Attackers also hit Check Point Spark firewalls and F5 BIG-IP APM instances [7]. According to GreyNoise, the Zyxel switch intrusions have been running since August, against devices mostly in Italy, the US, Taiwan, South Korea and other EU countries [8][9].

Those are sustained operations against internet-facing devices, and the exploitation dates are public [5][6][8]. TASK#STOMP needs a foothold on a Windows host before any of its collection starts [1].

What to watch

  • A full TASK#STOMP write-up naming delivery method, operator or victim count, to show whether the tool belongs to a campaign.
  • Gyazo's list of the exposed data fields, and whether credentials were among them.
  • Reports of CVE-2026-85102 moving from probing to confirmed compromise of Quantum Security Gateways.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories