Microsoft warns of NeedyMantis malware in targeted attacks
Microsoft researchers have identified ongoing attacks using a malware framework called NeedyMantis to maintain long-term access within already compromised networks. Active since at least October 2025, NeedyMantis has targeted telecoms, universities, government-linked organizations, and medical nonprofits. The malware is deployed manually by attackers, often hidden within legitimate open-source software using DLL sideloading. Microsoft attributes some activity to the Storm-3069 hacking group but has not found evidence of NeedyMantis spreading through a supply chain attack.
- NeedyMantis used to maintain access in breached networks
- Targets include telecoms, universities, and nonprofits
- Delivered via DLL sideloading inside open-source software
- Manual installation by hackers after gaining access
- Microsoft attributes some activity to group Storm-3069
Sources covering this
In this story
More in Cybersecurity
Critical zero-days in Citrix NetScaler exploited, patches released
Citrix has confirmed that two critical zero-day vulnerabilities affecting NetScaler ADC and Gateway devices have been exploited.
Dutch police arrest former hacker in ShinyHunters probe
Dutch police have arrested Pepijn van der Stap, a previously convicted hacker, in connection with an ongoing investigation into the…
Apple fixes CoreGraphics flaw after targeted attacks
Apple has released security updates for iOS, iPadOS, and macOS to fix a CoreGraphics vulnerability that may have been used in highly…
New Spectre BTR attack exposes Linux root password hashes
Researchers have unveiled a new Spectre Variant 2 attack, named Branch Target Reuse (BTR), that can extract root password hashes from…