Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
AI-summarised brief · reviewed before publication
Microsoft’s technical analysis revealed that the malware family NeedyMantis has been used by attackers to maintain long‑term access in a handful of targeted intrusions, including telecoms, universities, medical nonprofits, intergovernmental bodies, and government contractors. First identified in October 2025, NeedyMantis arrives as a bundle of a legitimate program, a malicious DLL, and an encrypted archive, employing DLL sideloading. The malware connects to a command‑and‑control server via HTTPS and WebSocket, allowing operators to load additional modules. Microsoft linked the activity to the Storm‑3069 group, likely originating in China, and noted its presence in the DAEMON Tools supply‑chain attack.
💡 Why It Matters
- · The discovery shows how sophisticated adversaries can embed persistent footholds in high‑value sectors, complicating detection and removal.
- · It underscores the need for vigilant monitoring of DLL sideloading and encrypted payloads in seemingly benign software.