Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
Microsoft says NeedyMantis malware maintained long-term access after targeted network breaches.
Microsoft analyzed NeedyMantis, malware used since at least October 2025 to keep access in a small number of intrusions at telecommunications firms, universities, medical nonprofits, intergovernmental organizations, and government contractors. It arrives as a legitimate program, a sideloaded DLL, and an encrypted archive, then contacts a command server over HTTPS before switching to WebSocket so operators can load modules. Microsoft links some use to Storm-3069, which it assesses appears to originate in China, and associates that group with the DAEMON Tools supply-chain attack tracked by Google as UNC6863, though it has not seen NeedyMantis delivered that way. Published indicators include three SHA-256 hashes, corp.tripswithengine[.]com, and Defender detections named TrojanDropper:Win64/NeedyMantis.