Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Uncovers New Malware for Stealthy Network Access

Microsoft Uncovers New Malware for Stealthy Network Access

Posted on September 28, 2026 By CWS

Microsoft’s Threat Intelligence team has identified NeedyMantis, a sophisticated malware framework, designed for maintaining clandestine access within networks that have already been compromised. This malware has been linked to a select number of targeted attacks on sectors including telecommunications, academia, and governmental bodies.

Targeted Sectors and Long-term Espionage

NeedyMantis has been detected in breaches involving telecommunications companies, educational institutions, and governmental organizations. The activity associated with this malware dates back to October 2025, indicating its use for prolonged espionage rather than general cybercrime.

Microsoft researchers stumbled upon NeedyMantis while analyzing indicators from the DAEMON Tools supply-chain breach, designated as Storm-3069. Although initially linked to China-based operations, Microsoft has not confirmed any specific state-sponsored group behind it.

Infection Mechanisms and Technical Details

The deployment of NeedyMantis is not directly tied to the compromised DAEMON Tools supply chain, suggesting different entry points for each target. A notable tactic includes the use of the Impacket toolkit to install malicious software alongside legitimate applications.

Operators utilize DLL sideloading to execute the malware, with legitimate applications loading malicious libraries disguised as essential components. Commonly exploited packages include Poedit, curl, and Vim, with files masquerading as well-known libraries.

Command and Control Capabilities

Once activated, NeedyMantis manages command-and-control communications and module downloads. Its configuration connects to corp.tripswithengine[.]com over port 443, exchanging system details through encoded and compressed methods.

Communication upgrades to WebSockets, employing XOR encoding and optional encryption. The malware can execute commands to manage modules and relay data, supporting persistent and adaptable network access.

Defensive Measures and Recommendations

Given its selective targeting, NeedyMantis poses a significant threat to organizations safeguarding critical infrastructure. Discovery of this malware should prompt thorough investigations into potential breaches, including credential theft and lateral movement.

Microsoft advises the implementation of various defensive strategies, such as cloud-delivered protection, network protection, and attack-surface-reduction rules to block untrusted executables. Security teams are urged to monitor for unusual connections and suspicious file activity.

Defender detections include specific alerts for TrojanDropper:Win64/NeedyMantis and associated behavior, providing crucial support for threat response teams.

Cyber Security News Tags:cyber attack, cyber defense, Cybersecurity, DLL Sideloading, Espionage, Impacket toolkit, Malware, malware framework, Microsoft, NeedyMantis, network intrusion, network security, security teams, Telecommunications, Trojan

Post navigation

Previous Post: IAM Frameworks for AI Agents: Ensuring Secure Operations
Next Post: Security Flaw Enables $388M Theft from Bitget Exchange

Related Posts

Critical SandboxJS Flaw Raises Security Concerns Critical SandboxJS Flaw Raises Security Concerns Cyber Security News
Hackers Exploit Polygon Blockchain for Stealth Malware Hackers Exploit Polygon Blockchain for Stealth Malware Cyber Security News
Hackers Allegedly Claim Breach Of HSBC USA Customers’ Records Including Financial Details Hackers Allegedly Claim Breach Of HSBC USA Customers’ Records Including Financial Details Cyber Security News
AsyncAPI Attack Exposes Cloud and API Credentials AsyncAPI Attack Exposes Cloud and API Credentials Cyber Security News
Windows Remote Desktop Gateway UAF Vulnerability Allows Remote Code Execution Windows Remote Desktop Gateway UAF Vulnerability Allows Remote Code Execution Cyber Security News
Scaly Wolf Attacking Organizations to Uncover Organizations’ Secrets Scaly Wolf Attacking Organizations to Uncover Organizations’ Secrets Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Expose AI-Driven Attack System
  • Security Flaw Enables $388M Theft from Bitget Exchange
  • Microsoft Uncovers New Malware for Stealthy Network Access
  • IAM Frameworks for AI Agents: Ensuring Secure Operations
  • Florida Seeks Court Order Against OpenAI’s ChatGPT

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Expose AI-Driven Attack System
  • Security Flaw Enables $388M Theft from Bitget Exchange
  • Microsoft Uncovers New Malware for Stealthy Network Access
  • IAM Frameworks for AI Agents: Ensuring Secure Operations
  • Florida Seeks Court Order Against OpenAI’s ChatGPT

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark