Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Uncovers New Malware for Stealthy Network Access

Microsoft Uncovers New Malware for Stealthy Network Access

Posted on September 28, 2026 By CWS

Microsoft’s Threat Intelligence team has identified NeedyMantis, a sophisticated malware framework, designed for maintaining clandestine access within networks that have already been compromised. This malware has been linked to a select number of targeted attacks on sectors including telecommunications, academia, and governmental bodies.

Targeted Sectors and Long-term Espionage

NeedyMantis has been detected in breaches involving telecommunications companies, educational institutions, and governmental organizations. The activity associated with this malware dates back to October 2025, indicating its use for prolonged espionage rather than general cybercrime.

Microsoft researchers stumbled upon NeedyMantis while analyzing indicators from the DAEMON Tools supply-chain breach, designated as Storm-3069. Although initially linked to China-based operations, Microsoft has not confirmed any specific state-sponsored group behind it.

Infection Mechanisms and Technical Details

The deployment of NeedyMantis is not directly tied to the compromised DAEMON Tools supply chain, suggesting different entry points for each target. A notable tactic includes the use of the Impacket toolkit to install malicious software alongside legitimate applications.

Operators utilize DLL sideloading to execute the malware, with legitimate applications loading malicious libraries disguised as essential components. Commonly exploited packages include Poedit, curl, and Vim, with files masquerading as well-known libraries.

Command and Control Capabilities

Once activated, NeedyMantis manages command-and-control communications and module downloads. Its configuration connects to corp.tripswithengine[.]com over port 443, exchanging system details through encoded and compressed methods.

Communication upgrades to WebSockets, employing XOR encoding and optional encryption. The malware can execute commands to manage modules and relay data, supporting persistent and adaptable network access.

Defensive Measures and Recommendations

Given its selective targeting, NeedyMantis poses a significant threat to organizations safeguarding critical infrastructure. Discovery of this malware should prompt thorough investigations into potential breaches, including credential theft and lateral movement.

Microsoft advises the implementation of various defensive strategies, such as cloud-delivered protection, network protection, and attack-surface-reduction rules to block untrusted executables. Security teams are urged to monitor for unusual connections and suspicious file activity.

Defender detections include specific alerts for TrojanDropper:Win64/NeedyMantis and associated behavior, providing crucial support for threat response teams.

Cyber Security News Tags:cyber attack, cyber defense, Cybersecurity, DLL Sideloading, Espionage, Impacket toolkit, Malware, malware framework, Microsoft, NeedyMantis, network intrusion, network security, security teams, Telecommunications, Trojan

Post navigation

Previous Post: IAM Frameworks for AI Agents: Ensuring Secure Operations

Related Posts

NSA Utilizes Anthropic’s AI Amid Pentagon Ban NSA Utilizes Anthropic’s AI Amid Pentagon Ban Cyber Security News
Critical WatchGuard Firebox Vulnerabilities Let Attackers Bypass Integrity Checks and Inject Malicious Codes Critical WatchGuard Firebox Vulnerabilities Let Attackers Bypass Integrity Checks and Inject Malicious Codes Cyber Security News
Mac Users Threatened by ClickFix Campaign with Atomic Stealer Mac Users Threatened by ClickFix Campaign with Atomic Stealer Cyber Security News
CISA Warns of Zimbra Collaboration Suite (ZCS) XSS Zero-Day Vulnerability Actively Exploited in Attacks CISA Warns of Zimbra Collaboration Suite (ZCS) XSS Zero-Day Vulnerability Actively Exploited in Attacks Cyber Security News
OpenAI Boosts AI Security by Acquiring Promptfoo OpenAI Boosts AI Security by Acquiring Promptfoo Cyber Security News
React Native Packages Targeted by Credential-Stealing Malware React Native Packages Targeted by Credential-Stealing Malware Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Uncovers New Malware for Stealthy Network Access
  • IAM Frameworks for AI Agents: Ensuring Secure Operations
  • Florida Seeks Court Order Against OpenAI’s ChatGPT
  • Modulate Secures $25M to Enhance Deepfake Detection
  • Cross-Platform File Notification Attack Exposes User Activity

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Uncovers New Malware for Stealthy Network Access
  • IAM Frameworks for AI Agents: Ensuring Secure Operations
  • Florida Seeks Court Order Against OpenAI’s ChatGPT
  • Modulate Secures $25M to Enhance Deepfake Detection
  • Cross-Platform File Notification Attack Exposes User Activity

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark