Microsoft says the NeedyMantis malware family has been used in targeted intrusions to maintain long-term access inside already breached networks across sectors such as telecommunications, universities, and government contractors. The activity overlaps with the DAEMON Tools supply chain incident and is linked to Storm-3069, with indicators including the C2 domain corp.tripswithengine[.]com and hashes tied to malicious DLL sideloading. #NeedyMantis #Storm3069 #DAEMONTools #UNC6863
Keypoints
- NeedyMantis has been used to keep persistent access in targeted intrusions.
- Victims include telecoms, universities, medical nonprofits, intergovernmental organizations, and contractors.
- The malware abuses DLL sideloading with legitimate tools like Poedit, curl, Vim, and TightVNC.
- Storm-3069 is Microsoftβs temporary name for one group using NeedyMantis.
- Microsoft published hashes, paths, and the corp.tripswithengine[.]com C2 domain for hunting.
Read More: https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html