Find notable cyber news and cases, enriched with sources, timelines, and signals.

NeedyMantis long-term access activity

Malware Activity
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

The NeedyMantis malware family is being used to maintain long-term access in already breached networks, affecting a small number of targeted intrusions across telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors. Microsoft says the activity dates back to October 2025. In examined cases, the malware arrived through DLL sideloading and established command-and-control over HTTPS and WebSocket. Microsoft published SHA-256 hashes, the corp.tripswithengine[.]com domain, file paths, and hunting queries to help defenders find it.

Related Happenings

Silver Fox bogus software-download websites campaign

Campaign
H score38 First: 02.09.2026 19:41 Last: 02.09.2026 19:41 Sources 1

About this happening: An active Silver Fox (aka Yinhu) campaign is using bogus software-download websites to impersonate trusted vendors and deliver malicious installers, exposing China-based...

ACR Stealer enterprise infostealer surge

Malware Activity
H score29 First: 18.07.2026 17:17 Last: 18.07.2026 17:17 Sources 1

About this happening: ACR Stealer attacks surged against enterprise customers, putting browser-stored passwords, authentication tokens, cookies, and sensitive documents at risk....

ACR Stealer browser credential and document theft activity

Malware Activity
H score29 First: 17.07.2026 11:56 Last: 17.07.2026 11:56 Sources 1

About this happening: ACR Stealer activity has expanded across enterprise environments, with Microsoft linking the malware to late April to mid-June 2026 campaigns that use ClickFix lur...

KongTuke ClickFix and Teams access-seeking campaign

Campaign
H score33 First: 25.06.2026 11:54 Last: 25.06.2026 11:54 Sources 1

About this happening: The KongTuke/Woodgnat campaign now includes Node.js/node.exe abuse to run attacker JavaScript and deploy payloads in targeted attacks against government departments*...

Latest development: 03.09.2026 13:43

KongTuke/Woodgnat actors have abused the signed Node.js/node.exe runtime to run attacker JavaScript and deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels since February 2026. One intrusion against an unspecified Asian technology company between March 23 and July 25, 2026 used the official Node.js installer from nodejs[.]org and EtherHiding to establish long-term access, and related attack chains also involve CrashFix, ModeloRAT, Mistic, GateKeeper, C2Looper, and AsukaStealer.

UNC5221 Brickstorm, Plenet, and AgentPSD access-maintenance malware activity

Malware Activity
H score16 First: 05.06.2026 21:09 Last: 05.06.2026 21:09 Sources 1

About this happening: The Brickstorm malware set enabled UNC5221 / VerdantBamboo to keep long-term access inside victim infrastructure, including Microsoft 365, raising the risk of stealthy...

Timeline

  1. 28.09.2026 21:35 2 articles · 2h ago

    NeedyMantis long-term access activity

    Initial Disclosure

    The earliest tracked NeedyMantis sample dates to October 2025, when an older version included a persistence module that used Windows services. Later samples seen in May 2026 led Microsoft to publish hashes, paths, domains, and hunting queries for defenders.

    Show sources