Threat Intelligence

New NeedyMantis Malware Gives Hackers Long-Term Backdoor Access to Breached Networks

The Hacker News · 29 Sept 2026
Key Takeaway Regularly verify the integrity of installed software and monitor for unusual DLL loading behaviour, especially from legitimate-looking programs, to catch sideloading attacks early.

Microsoft has published a technical analysis of NeedyMantis, a malware family used to maintain long-term access to networks that attackers have already broken into. It has appeared in a small number of targeted intrusions affecting telecommunications firms, universities, medical nonprofits, intergovernmental organisations, and government contractors, with activity dating back to at least October 2025.

Microsoft discovered the malware while investigating a supply chain attack on the DAEMON Tools Lite software, where signed installers were tampered with between April and May 2026. While one attack group, tracked as Storm-3069, was linked to that incident, Microsoft has not seen NeedyMantis itself distributed through a supply chain compromise. Instead, in observed cases, the malware arrives as a bundle containing a legitimate program, a malicious file disguised as one it normally loads, and an encrypted archive, a technique known as DLL sideloading. Legitimate tools misused this way include Poedit, curl, Vim, and TightVNC, as well as disguised files mimicking Microsoft Office, Broadcom, Intel, and NVIDIA components.

Once active, the malware unpacks further stages and establishes contact with a remote command server, later switching to a persistent connection that lets attackers load additional modules. Microsoft has not yet confirmed what those additional modules do, but has published file hashes, domains, and detection queries to help organisations check for signs of compromise.

malware persistence supply chain attack DLL sideloading threat intelligence
Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.