#Securonix
Securonix Uncovers Windows Backdoor That Enables Continuous Document Theft

Securonix Threat Research has released new research on TASK#STOMP, a Windows backdoor designed to maintain long-term access and continuously steal business documents....
Securonix Uncovers Windows Backdoor That Enables Continuous Document Theft
Securonix Threat Research has released new research on TASK#STOMP, a Windows backdoor designed to maintain long-term access and continuously steal business documents. The malware targets files across every fixed drive, monitors for new or modified documents and gives attackers ongoing remote access to the infected system. Key findings include: TASK#STOMP combines scheduled tasks, a Startup-folder launcher and rotating Windows-style task names to maintain persistence and evade detection.
itnerd.blog
September 21, 2026 at 2:00 PM
The latest update for #Securonix includes "Stop Chasing Tabs: Bringing Threat Research Home to the Browser" and "ISO/IEC 42001 and the Governance Gap Between Pilot and Production".

#cybersecurity #cloudsecurity #SIEM https://opsmtrs.com/4qmpzeX
Securonix
Securonix is transforming how security operations are delivered, measured, and scaled. Our Unified Defense SIEM combines SIEM, UEBA, SOAR, TIP, and TDIR in a single cloud-native platform that helps security teams detect threats faster, investigate with context, and respond with precision.
opsmtrs.com
September 24, 2026 at 2:11 AM
TASK#STOMP is a Windows backdoor that steals Wi-Fi passwords, screenshots, clipboard text, and business files, while keeping persistence to exfiltrate new documents. Likely delivered via phishing with ZIP or ISO attachments. #TASKSTOMP #Securonix
The TASK#STOMP Windows Backdoor Takes Wi-Fi Passwords, Screenshots, And Business Files
Researchers analyzed TASK#STOMP, a Windows backdoor that hunts for business documents, exfiltrates them, and persists to steal new or modified files while also collecting Wi-Fi credentials, clipboard text, screenshots, and operator commands. Securonix says the malware uses multiple footholds, likely arrives via phishing with a ZIP or ISO/IMG attachment, and shows no clear attribution to a known APT. #TASKSTOMP #Securonix #WindowsScriptHost #VBScript #PowerShell
www.hendryadrian.com
September 21, 2026 at 5:15 PM
The latest update for #Securonix includes "What Indian Banks Can Teach Every Enterprise About Real-Time Fraud Pressure" and "Digital Arrest Scams: One of India's Most Heinous Cybercrime Stories".

#cybersecurity #cloudsecurity #SIEM https://opsmtrs.com/4qmpzeX
Securonix
Securonix is transforming how security operations are delivered, measured, and scaled. Our Unified Defense SIEM combines SIEM, UEBA, SOAR, TIP, and TDIR in a single cloud-native platform that helps security teams detect threats faster, investigate with context, and respond with precision.
opsmtrs.com
July 30, 2026 at 3:10 AM
Securonix launches AI threat research agent and ThreatWatch validation tool

Securonix announced the Securonix Threat Research Agent and ThreatWatch for ThreatQ, expanding how security teams research threats, validate exposure, and turn intelligence into documented action. Built o…
#hackernews #news
Securonix launches AI threat research agent and ThreatWatch validation tool
Securonix announced the Securonix Threat Research Agent and ThreatWatch for ThreatQ, expanding how security teams research threats, validate exposure, and turn intelligence into documented action. Built on the ThreatQ platform and connected to Securonix security operations workflows, the new capabilities help teams generate role-specific intelligence, validate emerging threats against historical telemetry, and deliver explainable findings for analysts, SOC leaders, and executives. Security teams are under growing pressure to explain what is happening, why it matters, …
www.helpnetsecurity.com
May 9, 2026 at 9:40 AM
A RAT in the spreadsheet. [Research Saturday]

Today we are joined by Aaron Beardslee, Manager of Threat Research at Securonix, discussing "Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation." Securonix researchers have identified an evolved version of…
#hackernews #news
A RAT in the spreadsheet. [Research Saturday]
Today we are joined by Aaron Beardslee, Manager of Threat Research at Securonix, discussing "Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation." Securonix researchers have identified an evolved version of the SHEETCREEP espionage campaign, using a diplomatic-themed ISO phishing lure to deliver a C# remote access trojan targeting Indian diplomatic interests. The malware abuses the Google Sheets API as a stealthy command-and-control channel, with researchers identifying 91 active victim tabs, including a high-confidence target in Pakistan. The campaign, assessed with moderate confidence as linked to Pakistan-aligned APT36, has added XOR-obfuscated configurations and other anti-analysis techniques to evade detection and maintain persistent access. The research and executive brief can be found here: ⁠Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation
thecyberwire.com
August 23, 2026 at 12:08 PM
Securonix researchers identified a stealthy backdoor capable of exfiltrating business documents. TASK#STOMP uses encoded PowerShell scripts and Scheduled Tasks for persistent remote access. www.securonix.com/blog/task-st...
September 23, 2026 at 10:25 AM
The latest update for #Securonix includes "TASK#STOMP: PowerShell Backdoor for Document Theft and Remote Access" and "Clop Never Left: Inside the PTC Windchill Data Theft Campaign".

#cybersecurity #cloudsecurity #SIEM https://opsmtrs.com/4qmpzeX
Securonix
Securonix is transforming how security operations are delivered, measured, and scaled. Our Unified Defense SIEM combines SIEM, UEBA, SOAR, TIP, and TDIR in a single cloud-native platform that helps security teams detect threats faster, investigate with context, and respond with precision.
opsmtrs.com
September 22, 2026 at 12:43 AM
The latest update for #Securonix includes "VOID#GEIST: Stealthy MultiStage #Python Loader with Embedded Runtime Deployment, Startup Persistence, and Fileless Early Bird APC Injection into explorer.exe".

#cybersecurity #cloudsecurity #SIEM https://opsmtrs.com/4qmpzeX
Securonix
Securonix is transforming how security operations are delivered, measured, and scaled. Our Unified Defense SIEM combines SIEM, UEBA, SOAR, TIP, and TDIR in a single cloud-native platform that helps security teams detect threats faster, investigate with context, and respond with precision.
opsmtrs.com
March 6, 2026 at 3:11 AM
I worked for an enterprise security software company (Securonix) for about 4 years, and when I left to take a job at a data management startup I suddenly felt like a weight had been lifted off my shoulders. Having to think dark thoughts all day every day truly affects your life...
August 9, 2025 at 2:21 AM
Detecting LDAP enumeration and Bloodhound‘s Sharphound collector using AD Decoys

medium.com/securonix-te...
Detecting LDAP enumeration and Bloodhound‘s Sharphound collector using Active Directory Decoys
Using deception and decoy accounts to detect threat actors
medium.com
December 27, 2023 at 8:33 PM
Pakistan-focused phishing campaign uses tax-themed .pdf.msc files containing JavaScript. These download the DismCore.dll backdoor, establishing persistence and exfiltrating data. Securonix (FLUX#CONSOLE) stopped it after 24 hours.#PakTaxPhishing
December 17, 2024 at 3:05 PM
New by me @forbes.com : I can't confirm if they were standing on the toilet when they came up with the idea for the FLUX#CONSOLE Windows backdoor attack (see what I did there?) but I do know this great technical analysis by Securonix is well worth a read.

#infosec

www.forbes.com/sites/daveyw...
New Microsoft Hack Warning As Windows Backdoor Attackers Strike
Beware of this new Windows cyberattack. Here’s what you need to know about the Microsoft FLUX#CONSOLE Windows backdoor hacking campaign.
www.forbes.com
December 21, 2024 at 12:27 PM
Securonix names Toby Weiss as CEO

Securonix appoints Toby Weiss to lead its AI security push. The former Fiery chief executive will oversee the company’s next phase as SOCs move from alert management towards AI-powered execution.
Securonix names Toby Weiss as CEO
Securonix appoints Toby Weiss to lead its AI security push. The former Fiery chief executive will oversee the company’s next phase as SOCs move from alert management towards AI-powered execution.
businessquarter.co.uk
July 1, 2026 at 8:17 AM
The latest update for #Securonix includes "Data Pipeline Manager Flex Consumption (DPM Flex) Data Sheet" and "From Heritage to Horizon: The Evolution and Innovation of New Securonix To Become 6X Leader in #Gartner MQ for #SIEM".

#potatosecurity #clownsecurity https://opsmtrs.com/4qmpzeX
November 13, 2025 at 6:11 AM
The latest update for #Securonix includes "Securonix Threat Labs Monthly Intelligence Insights – November 2025" and "JS#SMUGGLER: Multi-Stage - Hidden Iframes, Obfuscated #JavaScript, Silent Redirectors & NetSupport RAT Delivery".

#cybersecurity #cloudsecurity #SIEM https://opsmtrs.com/4qmpzeX
Securonix
Securonix is transforming how security operations are delivered, measured, and scaled. Our Unified Defense SIEM combines SIEM, UEBA, SOAR, TIP, and TDIR in a single cloud-native platform that helps security teams detect threats faster, investigate with context, and respond with precision.
opsmtrs.com
December 17, 2025 at 1:29 AM
Criminal IP and Securonix ThreatQ Collaborate to Enhance Threat Intelligence Operations
Criminal IP and Securonix ThreatQ Collaborate to Enhance Threat Intelligence Operations
Raw threat intel isn't enough without real-world context. Criminal IP has partnered with Securonix to integrate exposure-based intelligence into ThreatQ, automating analysis and speeding up investigations.
www.bleepingcomputer.com
May 1, 2026 at 2:41 PM
Securonix Threat Research analyses VENOMOUS#HELPER, an ongoing phishing campaign that has hit more than 80 organizations since at least April 2025. The operation uses vendor-signed SimpleHelp and ScreenConnect RMM tools together to establish remote access. www.securonix.com/blog/venomou...
May 5, 2026 at 9:30 AM
The latest update for #Securonix includes "In #AI, No One Can Hear the Sandbox Scream" and "Threat Analytics for Microsoft Sentinel".

#cybersecurity #cloudsecurity #SIEM https://opsmtrs.com/4qmpzeX
Securonix
Securonix is transforming how security operations are delivered, measured, and scaled. Our Unified Defense SIEM combines SIEM, UEBA, SOAR, TIP, and TDIR in a single cloud-native platform that helps security teams detect threats faster, investigate with context, and respond with precision.
opsmtrs.com
August 5, 2026 at 3:42 AM
Russia-linked hackers are getting malware into European hotels and other hospitality outfits by tricking staff into installing it themselves through fake Windows Blue Screen of Death (BSOD) crashes, Securonix threat researchers say
Hotel staff tricked into installing malware by bogus BSODs
: Phishers posing as Booking.com use panic-inducing blue screens to bypass security controls
www.theregister.com
January 6, 2026 at 2:31 PM
#CyberThreats #China #Ransomware #ThreatResearch The 2024 Cyber Threat Report shows a rise in sophisticated attacks, including APTs targeting critical sectors. LockBit ransomware resurfaces, exploiting *Ivanti* and *GlobalProtect* vulnerabilities. 🌐
www.hendryadrian.com/securonix-th...
Securonix Threat Labs 2024 Annual Autonomous Threat Sweeper Intelligence Insights – Cybersecurity News Everyday
www.hendryadrian.com
January 16, 2025 at 8:52 AM