#MalWare
NeedyMantis Malware Expands the Post-Compromise Threat Landscape #Cybersecurity #DLLSideloading #malware
NeedyMantis Malware Expands the Post-Compromise Threat Landscape
A modular malware family dubbed NeedyMantis has been identified by Microsoft Threat Intelligence, and has been employed to maintain access to compromised systems in a limited number of targeted intrusions.  Evidence of the malware dating back to at least October 2025 indicates that it has affected telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. During an investigation into indicators associated with the DAEMON Tools supply chain compromise, Microsoft identified NeedyMantis.  The company tracks activity associated with Storm-3069, and has observed the malware in use beyond that campaign. While Microsoft believes the observed operations are associated with activities associated with China-based threat actors, it has not attributed Storm-3069 to a Chinese nation state actor or confirmed that all NeedyMantis activity originated from a single operator.  As a general rule, NeedyMantis is deployed after attackers have already gained access to the target environment. The malware serves primarily as an initial access tool, but it is also intended to maintain access and facilitate further activity within the compromised network, utilizing DLL sideloading as part of its delivery chain. It has been observed that attackers packaged malicious DLLs with legitimate applications and encrypted archives in an attempt to facilitate their delivery.  Poedit, curl, Vim, and TightVNC were among the programs abused in this manner, while malicious DLLs were disguised as Microsoft Office, Broadcom, Intel, and NVIDIA components. One incident involved the use of Impacket toolkit to copy a legitimate software package from a network share into the malicious file, which was then executed on the targeted computer. It is important to note that NeedyMantis played a crucial role in the post-compromise phase of an intrusion, despite the attacker already having established access to the environment.  Once the initial DLL is loaded, the malware continues to feature layered security. A second-stage component is extracted from the encrypted archive by the first-stage loader, which is the file used in the analysis, encryptbase64.ps1. Even though the file has a PowerShell extension, it contains x64 shellcode rather than a conventional PowerShell script.  Once the embedded malware has been decoded and decompressed, a custom executable format based on a reduced version of the Windows PE format is loaded. An additional level of protection can be provided by the custom archive. Its contents can vary between samples, with file names and internal values varying.  The analyzed WinSparkle archive contained legitimate components of 7-Zip and Sysinternals as well as files with familiar Windows library names, including dnsapi.dll and ws2_32.dll, mixed with legitimate components. Instead of the legitimate libraries represented by these files, NeedyMantis configuration and communication components were found in these files. The main component communicates with the malware's command-and-control infrastructure and manages additional modules.  It is Microsoft's responsibility to observe an initial HTTPS request before switching the connection to a binary WebSocket protocol. The communications component utilizes WebSockets. A hard-coded user agent for Firefox 21.0 has also been used by the malware in one implementation. Through the C2 channel, operators can add and remove modules and exchange data with them, though Microsoft has not confirmed the specific functionality of the modules.  A NeedyMantis sample collected in October of 2025 contained a persistence module based on Windows services, however the persistence method employed by the newer analyzed sample has not been identified. The malware is more challenging to analyze through a single file or indicator due to its staged loading, misleading file names, encrypted archives, and modular C2 communication.  Detection points have been provided by Microsoft for hashes, file paths, the C2 hostname corp.tripswithengine[.]com, and the Firefox/21.0 user agent. As a result of the NeedyMantis campaign, security teams need to monitor suspicious loaders, C2 traffic, and unusual usage of legitimate software in order to recognize the risks posed by modular post-compromise malware.
dlvr.it
September 29, 2026 at 2:42 PM
yep. my biggest issue is just how defeatist it is. every website maintainer just learned that they've been vulnerable to a fairly simple ddos-shaped issue. rather than solving that, they decided to run malware on the user's machine and hope the problem will go away in the future.
September 29, 2026 at 2:40 PM
We ran a Hugging Face-style agentic attack against our platform and published the scorecard. No malware and no human login, just one service account crossing four systems.

The third column is for your stack. https://loom.ly/1c7t9zg
September 29, 2026 at 2:34 PM
RatHat Android Trojan Adopts AI-Driven Malware-as-a-Service Model

The RatHat Android banking trojan has evolved into a sophisticated malware-as-a-service operation, using Google Gemini to rank high-value victims and navigate banking apps.
RatHat Android Trojan Adopts AI-Driven Malware-as-a-Service Model
The RatHat Android banking trojan has evolved into a sophisticated malware-as-a-service operation, using Google Gemini to rank high-value victims and navigate banking apps.
privacyneedle.com
September 29, 2026 at 2:33 PM
Stop relying on annual audits to prove your security works.

With Armornet, every block and allow is logged as evidence for your risk register.

We rank vendors by what they actually ship. Every decision, measured.

Request Alpha: armornet.io

#DevSecOps #CyberSecurity #SoftwareSupplyChain
September 29, 2026 at 2:25 PM
SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers
SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers
Fake software download pages are drawing Windows users into a Silver Fox-linked malware campaign. The pages imitate familiar vendors and supply installers that can leave an infected computer vulnerable to continued access. Microsoft has observed compromises across several industries, mainly affecting Chinese-speaking users. The attackers rely on a simple habit: people search for an application, recognize its branding, and click download. Other Silver Fox-related activity has used messages and attachments. Researchers at Pelagos Intel identified one such separate chain involving a finance-themed WhatsApp message aimed at a Malaysian recipient. The attachment carried a signed program and an unsigned library. That finding does not establish that the WhatsApp operation used the counterfeit websites. Microsoft assesses the fake-installer campaign as consistent with Silver Fox, also called Yinhu, with moderate confidence. It has not attributed the operation to a nation-state actor. Pelagos Intel said in a report shared with Cyber Security News (CSN) that its separately analyzed files established persistence and repeatedly attempted to reach an external server. SilverFox Hackers Built Fake Software Sites The cloned pages copy the look of legitimate software download sites, including pages for browsers, security tools, and everyday utilities. Microsoft traced visitors from a counterfeit page to a download host serving a ZIP archive. Its Silver Fox fake installer investigation describes how familiar branding can hide a dangerous installation chain. Infection Chain (Source – Pelagos Intel) Two archives with the same name arrived roughly 69 seconds apart, yet contained different material. Microsoft says the archive can be rebuilt for each request while its name and download address stay the same. That makes a single archive hash a poor way to recognize every copy, but it is not evidence that the websites identify and selectively deceive security researchers. Once opened, the archive launches a wrapper that places malicious code in a randomly named Windows folder. Another observed route runs through Windows Installer, a system component. A user expecting a routine installation may therefore miss the extra program starting in the background, especially when the visible download page looks convincing. This approach has precedent: a fake security software download was previously linked to a Silver Fox-related infection. These were separate operations. They do, however, show why recognizable branding and apparently ordinary installers deserve closer scrutiny when the download source cannot be verified. Persistence And Detection Clues Microsoft found that later stages created scheduled tasks to restart malicious programs and briefly ran a task with high system privileges to change security exclusions. The malware also tried to disable Windows Update, remove recovery copies, and contact attacker-controlled infrastructure. Such changes can make both discovery and cleanup harder after the original installer has closed. Valid Authenticode signature (Source – Pelagos Intel) Pelagos Intel’s WhatsApp case followed a different technical route. A validly signed launcher called functions in an unsigned library that presented itself as a Windows desktop component. The library decoded data and copied transformed content into executable memory. The same files were then copied into a user profile, with a startup registry entry set to run them again. During testing, Pelagos recorded 96 connection attempts about three seconds apart. It also observed a successful decryption operation whose length matched a transformation identified during code analysis. These observations support a configured, persistent loader, but the report does not demonstrate that this chain and Microsoft’s fake-site campaign are the same intrusion. Earlier reporting on trusted software loading malware illustrates why a valid signature on one file cannot clear every neighboring component. Likewise, tax themed Silver Fox lures show that an apparently credible document or message can be the first step toward a separate infection. These links provide context, not proof of shared infrastructure. This distinction matters when teams compare samples and reports. For the counterfeit-site campaign, Microsoft recommends downloading from verified sources, watching for unexpected archive downloads, and alerting on suspicious scheduled tasks or security-setting changes. For the WhatsApp chain, Pelagos highlights the unusual startup entry, staged file pair, and regular outbound attempts as useful investigation leads. Teams should verify which chain they are investigating before applying the indicators below. Indicators of Compromise (IoCs):- Type Indicator Description SHA-256 9F2CAEDA208C9D729B44F31C32B5E1EEEF18D84D6E36B04AFE15D894D3809672 Delivered ZIP archive SHA-256 E2BF8B7CD396EE950A5B6911EA098C2E49D4ED002A6C04D5D660CCD4F7D66BAA IMG disk image SHA-256 F712C2A8B4ABF2E299A2B480020333DEB0F43364E9686CDA78B1243C62E4830D Signed executable SHA-256 C1E184615241FE69DB3BF4093A22C7C0BF5D6072D2F51E558142B844E871084F Unsigned companion DLL Network endpoint 134.122.155.135:443 Repeated outbound connection attempts File name PDF_C2841_20260911100446.zip WhatsApp attachment File name PDF_C2089_20260911100446.exe Signed executable File name active_desktop_render_x64.dll Companion DLL Staging path %APPDATA%\Microsoft\Update\ Directory used to stage both files Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run Startup persistence location Registry value MicrosoftUpdate Observed startup value name Signer Guangzhou Kugou Technology Co., Ltd. Signer identified for the executable Certificate thumbprint 757BDD02CBA91CA59C46E2098A5479C1ABC1FDBE Certificate identifier PDB path D:\buildbot\build1\desktop_screen\build\bin\active_desktop_launcher_x64.pdb Build-path artifact Configuration marker @@RAPID_CFG_START@@ Marker found in decrypted data File metadata active_desktop_launcher.exe Executable identity in version resources File metadata dwmapi.dll Original filename claimed in DLL metadata Hunting string ReleaseFromExplorer Static-analysis clustering term Hunting string _ipcfr_wqkqzk Static-analysis clustering term Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers appeared first on Cyber Security News .
cybersecuritynews.com
September 29, 2026 at 2:20 PM
¿Tenéis idea de porqué me sale este mensaje en el móvil?
Es al hacer una búsqueda en Brave sin tener nada en marcha ni en el teléfono ni en el PC ni en la tablet.
He pasado tests de malware en el teléfono y en el PC y no detectan nada.
September 29, 2026 at 2:20 PM
A group of hackers is targeting businesses to gain long-term access to their private networks. If you use…
Source: Infosecurity Magazine
Read: https://www.infosecurity-magazine.com/news/microsoft-needymantis-malware/
#Cyzo #CyberSecurity #DataProtection #BusinessSafety #OnlineSecurity
September 29, 2026 at 2:20 PM
Malware uses HashHiding: hiding IPs and ports in Ethereum addresses. #BlockchainThreat #Ethereum #Malware #Security #HashHiding #CyberDefense thedailytechfeed.com/malware-uses...
September 29, 2026 at 2:18 PM
JadePuffer AI Attacks Target Azure Cloud Resources

The malware emerged in July and evolved quickly. Cloud security firm Sysdig flagged its use of AI agents to automate... #MicrosoftAzure
JadePuffer AI Attacks Target Azure Cloud Resources
Azure cloud environments are facing a new and destructive threat from the JadePuffer ransomware operator. The group uses AI agents to automate reconnaissance, steal credentials, and destroy critical cloud resources, all with minimal human intervention once the attack begins. The malware emerged in July and evolved quickly. Cloud security firm Sysdig flagged its use of […]
hashlytics.io
September 29, 2026 at 2:14 PM
Fake Razer and Edge download sites rebuild the installer per request - hash blocking is useless. https://intel.threadlinqs.com/threat/TL-2026-2773 #ThreatIntel #ValleyRAT #Ghost #Silver
September 29, 2026 at 2:04 PM
Nep-downloadcampagnes misleiden gebruikers met geavanceerde technieken, malware-

Nep-software-downloadpagina's, die zich voordoen als legitieme leveranciers van populaire applicaties zoals browsers, beveiligingstools en algemene hulpprogramma's, maken gebruik van de gewoonte van gebruikers ...
Nep-downloadcampagnes misleiden gebruikers met geavanceerde technieken, malware-campagnes getraceerd tot Silver Fox.
Nep-software-downloadpagina's, die zich voordoen als legitieme leveranciers van populaire applicaties zoals browsers, beveiligingstools en algemene hulpprogramma's, maken gebruik van de gewoonte van gebruikers om bij het zoeken naar software direct op de downloadknop te klikken. Deze misleidende pagina's leiden Windows-gebruikers naar een malwarecampagne die geassocieerd wordt met Silver Fox, ook wel bekend als Yinhu. Bezoekers van deze nep-pagina's worden doorgestuurd naar een downloadhost die een ZIP-archief aanbiedt. Opmerkelijk is dat twee archieven met dezelfde naam bijna gelijktijdig kunnen worden gedownload, maar met verschillende inhoud. Dit betekent dat het analyseren van een enkel...
newsfacts.info
September 29, 2026 at 2:01 PM
Endpoint Vulnerabilities: Signal cannot protect against a compromised device. If a phone is physically seized, hacked via malware, or unlocked, messages can be read directly.
September 29, 2026 at 1:50 PM
On the one hand, Muse is vibe coded slop malware. On the other hand you could get a $32 check in 10 years if you let it build a stasi file on you and everyone you know or meet.
September 29, 2026 at 1:49 PM
On the other hand, it’s a nested doll of malware with no real harness not to do that in general.

A bunch of claude-coded prefilled prompts and skills and an invisible layer that builds surveillance files about everyone you meet.

neuromatch.social/@jonny/11733...
jonny (nonvenomous) (@jonny@neuromatch.social)
It created memory files that say "explore and do everything except try to escape the container" but since I can edit all the files I just changed that to say "explore and do everything including escap...
neuromatch.social
September 29, 2026 at 1:47 PM
NeedyMantis is a modular post-compromise malware identified by Microsoft Threat Intelligence, primarily targeting telecommunications, universities, and government contractors.
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
www.microsoft.com
September 29, 2026 at 1:47 PM
--Ransomware disrupts Japanese railway operator’s hotel systems,
--Japan's Times Car confirms breach of 6.6m accounts,
--Hackers steal data on 340 Swiss broadcasting staff,
--Microsoft finds China-linked NeedyMantis malware in selective attacks, 3/5
September 29, 2026 at 1:47 PM
SilverFox clones software sites and uses signed launchers with malware—common apps masking hidden threats. #SecurityNews #ThreatIntelligence #Malware #SilverFox #WindowsSecurity thedailytechfeed.com/silverfox-ma...
September 29, 2026 at 1:46 PM
Microsoft Warns NeedyMantis Malware Enables Persistent Network Access

Researchers attribute it to a Chinese operation, but they don't go as far to link it to the Chinese state... 👀

www.infosecurity-magazine.com/news/microso...
Microsoft Warns NeedyMantis Malware Enables Persistent Network Access
Microsoft Threat Intelligence warns that NeedyMantis threat actor from China has targeted organizations across a range of industries
www.infosecurity-magazine.com
September 29, 2026 at 1:41 PM
Microsoft Identifies NeedyMantis Malware Used for Persistent Network Access

Microsoft Threat Intelligence has identified NeedyMantis, a stealthy malware framework used by Chinese-linked actors to maintain persistent access in telecommunications, academic, and government networks.
Microsoft Identifies NeedyMantis Malware Used for Persistent Network Access
Microsoft Threat Intelligence has identified NeedyMantis, a stealthy malware framework used by Chinese-linked actors to maintain persistent access in telecommunications, academic, and government networks.
privacyneedle.com
September 29, 2026 at 1:34 PM
Scope a narrower set of requirements. Check for outdated or vulnerable software and enforce use of anti-virus/anti-malware software with a minimum scan frequency. Use risk based decisions to identify any additional requirements that should carry over.
September 29, 2026 at 1:32 PM
installed this malware onto my pc
September 29, 2026 at 1:15 PM
Threat Actors Use Custom ChatGPT GPTs to Deploy ClickFix Malware

A new ClickFix campaign is leveraging personalised ChatGPT Custom GPTs to social engineer users into executing malicious code on their machines.
Threat Actors Use Custom ChatGPT GPTs to Deploy ClickFix Malware
A new ClickFix campaign is leveraging personalised ChatGPT Custom GPTs to social engineer users into executing malicious code on their machines.
privacyneedle.com
September 29, 2026 at 1:13 PM