Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
- ID
- 29497
- Status
- summarized
- Published
- 29 Sep 2026, 2:35 AM
- Fetched
- 29 Sep 2026, 4:59 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.5
- Created
- 29 Sep 2026, 5:02 AM
- Tags
- Audience
- developerssaas_founders
What happened
Microsoft published a technical analysis of NeedyMantis, a malware family used to keep long-term access in networks that were already breached, seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors, with use dating back to at least October 2025. Microsoft found it while following indicators from Kaspersky's investigation into the DAEMON Tools supply chain attack, where signed DAEMON Tools Lite installers carried malicious code from April 8, 2026 until the developer replaced them with a clean version on May 5; Microsoft tracks that activity as Storm-3069. NeedyMantis arrives via DLL sideloading — a legitimate program plus a malicious DLL named after a file that program loads, plus an encrypted archive of the same name — using hosts including Poedit, curl, Vim, and TightVNC, and posing as DLLs from Microsoft Office, Broadcom, Intel, and NVIDIA, then connecting to C2 over HTTPS and switching to WebSocket.
Why it matters
If you ship or depend on signed Windows desktop installers, the concrete lesson is the April 8 to May 5, 2026 DAEMON Tools Lite window and the sideloading pattern: a trusted exe (Poedit, curl, Vim, TightVNC) sitting next to a same-named malicious DLL. Microsoft published file hashes, domains, file paths, and hunting queries, so the actionable step is to run those indicators rather than assume your EDR caught it — and to stop placing third-party binaries in writable directories beside signed executables you ship.
Discussion angle
Why DLL sideloading still works: these hosts load a DLL from their own directory, so a swapped WinSparkle.dll next to Poedit is enough — worth debating whether desktop app developers should pin or verify DLL loads, and whether the Impacket-based lateral movement via a network share changes how you segment build and release machines.