AI Weekly Malaysia

Back to items Summaries

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

ID
29497
Status
summarized
Published
29 Sep 2026, 2:35 AM
Fetched
29 Sep 2026, 4:59 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
4.5
Created
29 Sep 2026, 5:02 AM
Tags
Audience
developerssaas_founders

What happened

Microsoft published a technical analysis of NeedyMantis, a malware family used to keep long-term access in networks that were already breached, seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors, with use dating back to at least October 2025. Microsoft found it while following indicators from Kaspersky's investigation into the DAEMON Tools supply chain attack, where signed DAEMON Tools Lite installers carried malicious code from April 8, 2026 until the developer replaced them with a clean version on May 5; Microsoft tracks that activity as Storm-3069. NeedyMantis arrives via DLL sideloading — a legitimate program plus a malicious DLL named after a file that program loads, plus an encrypted archive of the same name — using hosts including Poedit, curl, Vim, and TightVNC, and posing as DLLs from Microsoft Office, Broadcom, Intel, and NVIDIA, then connecting to C2 over HTTPS and switching to WebSocket.

Why it matters

If you ship or depend on signed Windows desktop installers, the concrete lesson is the April 8 to May 5, 2026 DAEMON Tools Lite window and the sideloading pattern: a trusted exe (Poedit, curl, Vim, TightVNC) sitting next to a same-named malicious DLL. Microsoft published file hashes, domains, file paths, and hunting queries, so the actionable step is to run those indicators rather than assume your EDR caught it — and to stop placing third-party binaries in writable directories beside signed executables you ship.

Discussion angle

Why DLL sideloading still works: these hosts load a DLL from their own directory, so a swapped WinSparkle.dll next to Poedit is enough — worth debating whether desktop app developers should pin or verify DLL loads, and whether the Impacket-based lateral movement via a network share changes how you segment build and release machines.

Top