Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
NeedyMantis Malware Ensures Long-Term Network Access

NeedyMantis Malware Ensures Long-Term Network Access

Posted on September 28, 2026 By CWS

Microsoft has identified a malware strain named NeedyMantis that hackers use to ensure prolonged access to compromised networks. This discovery was made during an analysis of cyber threats affecting various sectors such as telecommunications, academia, and government contractors. The presence of NeedyMantis has been traced back to at least October 2025, indicating its persistent threat in the cybersecurity landscape.

Details of the NeedyMantis Malware

NeedyMantis was uncovered while Microsoft was investigating indicators from Kaspersky’s research on a supply chain attack involving DAEMON Tools. In this attack, malicious code was embedded into DAEMON Tools Lite installers, which were publicly available from April 8, 2026, until clean versions replaced them on May 5. Activity associated with this attack is tracked by Microsoft under the identifier Storm-3069, a group believed to be utilizing NeedyMantis. However, the spread of the malware through a supply chain attack has not been directly observed.

The malware comprises three components: a legitimate application, a malicious DLL masquerading as a legitimate file, and an encrypted archive sharing the DLL’s name. Once the application runs, the DLL is loaded, employing a technique known as DLL sideloading. Common legitimate applications used include Poedit, curl, and TightVNC. Notably, in Microsoft’s detailed analysis, the malware replaced the WinSparkle.dll file used by Poedit.

Operational Tactics and Impact

Upon execution, the malicious DLL extracts and initiates the malware’s main component from the encrypted archive. This component establishes communication with a command-and-control server over HTTPS, transitioning to a WebSocket connection to facilitate additional module loading. The further functions of these modules remain unconfirmed. An older version of NeedyMantis included a persistence module for Windows services, but details on how the newer version maintains its presence are not provided.

Microsoft has attributed Storm-3069’s operations to originate from China, though no direct links to specific state actors have been established. The malware’s deployment aligns with Chinese interests, as observed in the targeted organizations. Furthermore, the Google Threat Intelligence Group and Mandiant have linked the DAEMON Tools campaign to another entity, UNC6863, suspected to have connections to China.

Detection and Defense Strategies

To counter NeedyMantis, Microsoft has released several indicators of compromise, including SHA-256 hashes and file paths for malicious DLLs. They recommend using Microsoft Defender Antivirus, which recognizes the threat as TrojanDropper:Win64/NeedyMantis. Security settings such as cloud-delivered protection and network protection are advised to mitigate risks.

Additionally, Microsoft suggests vigilance in monitoring outbound network traffic for connections to the command-and-control domain. Users of the affected DAEMON Tools Lite version are advised to uninstall it, conduct a full system scan, and update to the latest version to safeguard against potential threats.

As cybersecurity threats evolve, staying informed and adopting recommended defense measures is crucial in protecting networks against sophisticated malware like NeedyMantis.

The Hacker News Tags:China-nexus, cyber threats, Cybersecurity, DAEMON Tools, DLL Sideloading, Hacking, Malware, Microsoft, NeedyMantis, network defense, network security, Storm-3069, supply chain attack, UNC6863

Post navigation

Previous Post: OpenCode Vulnerability Risks Unauthorized Code Execution
Next Post: Oracle PeopleSoft Vulnerability Exploited by ShinyHunters

Related Posts

ConnectWise Hit by Cyberattack; Nation-State Actor Suspected in Targeted Breach ConnectWise Hit by Cyberattack; Nation-State Actor Suspected in Targeted Breach The Hacker News
Researchers Expose Cyber Scheme Using Fake Installers Researchers Expose Cyber Scheme Using Fake Installers The Hacker News
Microsoft Identifies Three Salesforce Threat Vectors Microsoft Identifies Three Salesforce Threat Vectors The Hacker News
94% of Cyber Incidents Involve Anonymized Networks 94% of Cyber Incidents Involve Anonymized Networks The Hacker News
UNC6671 Cyber Threat Intensifies with Vishing Attacks UNC6671 Cyber Threat Intensifies with Vishing Attacks The Hacker News
How Can Retailers Cyber-Prepare for the Most Vulnerable Time of the Year? How Can Retailers Cyber-Prepare for the Most Vulnerable Time of the Year? The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • RatHat Android Malware Uses AI for Victim Targeting
  • Oracle PeopleSoft Vulnerability Exploited by ShinyHunters
  • NeedyMantis Malware Ensures Long-Term Network Access
  • OpenCode Vulnerability Risks Unauthorized Code Execution
  • Apple Fixes CoreGraphics Vulnerability in Older OS

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • RatHat Android Malware Uses AI for Victim Targeting
  • Oracle PeopleSoft Vulnerability Exploited by ShinyHunters
  • NeedyMantis Malware Ensures Long-Term Network Access
  • OpenCode Vulnerability Risks Unauthorized Code Execution
  • Apple Fixes CoreGraphics Vulnerability in Older OS

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark