Microsoft has identified NeedyMantis, a malware family used to maintain access within previously compromised networks. The threat has appeared in a limited number of targeted incidents involving telecommunications organizations, universities, medical nonprofits, intergovernmental bodies, and government contractors. Activity associated with the malware dates back to at least October 2025. Microsoft discovered NeedyMantis while investigating indicators connected to Kaspersky’s research into the DAEMON Tools supply-chain compromise. Microsoft tracks related activity as Storm-3069 but has not confirmed that NeedyMantis was delivered through the compromised DAEMON Tools installers. The malware is commonly packaged with three components: a legitimate executable, a malicious DLL named after a library normally loaded by that executable, and an encrypted archive sharing the DLL’s name. When the legitimate application starts, it loads the malicious DLL through DLL side-loading. Observed legitimate applications include Poedit, curl, Vim, and TightVNC, while some samples impersonated DLLs associated with Microsoft Office, Broadcom, Intel, and NVIDIA. In one incident, attackers already inside the network used the Impacket toolkit to copy the malware bundle from a network share and execute it on another system. After execution, the malicious DLL extracts an encrypted payload and launches the main malware component. NeedyMantis communicates with its command-and-control infrastructure through HTTPS before switching to WebSocket communications, allowing operators to manage additional modules and exchange information. An earlier sample contained Windows-service persistence, although the persistence method in newer versions remains unknown. Microsoft assesses that Storm-3069 activity may originate from China but has not linked it to a specific state-sponsored actor. Organizations should enable Defender cloud protection, Block at First Sight, EDR in Block Mode, Network Protection, attack disruption, and appropriate attack-surface-reduction rules. Teams should also investigate suspicious DLL side-loading and unexpected outbound C2 connections.
A newly demonstrated security flaw in LibreOffice and Apache OpenOffice shows how seemingly legitimate spreadsheet features can be combined to execute malicious code without the us...
Four vulnerabilities disclosed in Apache Struts could expose affected applications to remote code execution, denial of service, resource exhaustion, and cross-user data disclosure....
Atlassian has disclosed a critical arbitrary file access vulnerability, CVE-2026-21589, affecting Jira Software Data Center and Confluence Data Center. Rated CVSS 9.3, the flaw all...