Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
Microsoft says the NeedyMantis malware family has been used in targeted intrusions to maintain long-term access inside already breached networks across sectors such as telecommunications, universities, and government contractors. The activity overlaps with the DAEMON Tools supply chain incident and is linked to Storm-3069, with indicators including the C2 domain corp.tripswithengine[.]com and hashes tied to malicious DLL sideloading. #NeedyMantis #Storm3069 #DAEMONTools #UNC6863

Keypoints

  • NeedyMantis has been used to keep persistent access in targeted intrusions.
  • Victims include telecoms, universities, medical nonprofits, intergovernmental organizations, and contractors.
  • The malware abuses DLL sideloading with legitimate tools like Poedit, curl, Vim, and TightVNC.
  • Storm-3069 is Microsoft’s temporary name for one group using NeedyMantis.
  • Microsoft published hashes, paths, and the corp.tripswithengine[.]com C2 domain for hunting.

Read More: https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html