Monday, September 28, 2026

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis.

The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use goes back to at least October 2025.

Microsoft found NeedyMantis while following up on indicators from Kaspersky's investigation into the supply chain attack on DAEMON Tools. In that attack, official, signed installers for the DAEMON Tools Lite disk image program carried malicious code from April 8, 2026. The developer replaced them with a clean version on May 5.

Microsoft tracks the activity tied to that attack as Storm-3069. It says Storm-3069 is one group that uses NeedyMantis, though it has not seen the malware itself spread through a supply chain attack. Defenders can check their networks using the file hashes, domains, file paths, and hunting queries that Microsoft published and listed below.

How NeedyMantis Runs

In the cases Microsoft examined, NeedyMantis arrived as a bundle of three parts: a copy of a legitimate program, a malicious DLL named after a file that program loads, and an encrypted archive with the same name as the DLL. When the program starts, it loads the malicious DLL. This is called DLL sideloading.

The legitimate programs used this way include the Poedit translation tool, curl, the Vim text editor, and the TightVNC remote access tool. The malware has also posed as DLL files from Microsoft Office, Broadcom, Intel, and NVIDIA.

Cybersecurity

In the sample Microsoft analyzed in detail, the malicious file replaced WinSparkle.dll, the update component that Poedit uses.

In one intrusion, an operator who was already inside the network used the Impacket toolkit to copy the bundle from a network share and run it on a target machine. How attackers initially gain access to a network may differ from one intrusion to the next.

Once loaded, the DLL unpacks the next stage from the encrypted archive and runs it. That stage decodes the malware's main component. The main component connects to a command-and-control (C2) server over HTTPS and then switches to a WebSocket connection.

Through that connection, operators can load and unload extra modules and send data to them. Microsoft has not confirmed what those modules do.

An older version, seen in October 2025, included a persistence module that uses Windows services. Microsoft did not describe how the newer version it analyzed stays on a machine.

Who Is Behind It

Storm-3069 is a temporary name. Microsoft gives "Storm" names to new or developing groups until it is confident about who is behind them or where they come from.

Microsoft has also seen NeedyMantis outside Storm-3069's activity in the DAEMON Tools campaign, and it says more than one group may be using the malware. It has not determined whether all the activity comes from a single actor, nor has it explained what links Storm-3069 to NeedyMantis.

Storm-3069's activity appears to originate in China, Microsoft assesses, but the company has not tied the group to a Chinese nation-state actor. All the NeedyMantis activity Microsoft has seen so far fits the pattern of groups it links to China. Examples include targets that align with Chinese interests and the malware's use against only a few selected organizations.

When Kaspersky disclosed the DAEMON Tools attack in May, it found Chinese-language text in the malware but did not attribute it to any particular group.

Google Threat Intelligence Group tracks the actor behind the DAEMON Tools campaign as UNC6863. In June, Mandiant described UNC6863 as "a suspected China-nexus actor" that used the DAEMON Tools compromise to deploy malware. It is unclear whether UNC6863 and Storm-3069 belong to the same group.

How to Check for NeedyMantis

Microsoft published these indicators of compromise:

  • SHA-256: e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e (first-stage loader WinSparkle.dll, first seen May 21, 2026)
  • SHA-256: 9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef (encrypted archive named WinSparkle, first seen May 23, 2026)
  • SHA-256: c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77 (encrypted archive named libcurl, older version, first seen October 3, 2025)
  • Domain: corp.tripswithengine[.]com (C2 server, port 443)
  • User agent: firefox/21.0 (hard-coded in the malware's communications DLL)

These are some of the file paths used by the malicious DLLs:

  • %ProgramFiles%\Poedit\WinSparkle.dll
  • %ProgramData%\USOShared\libcurl.dll
  • %ProgramData%\VIM\vim64.dll
  • %ProgramData%\TightVNC\VIM\vim64.dll
  • %ProgramData%\office\dbghelp.dll
  • %ProgramData%\broadcom\dbghelp.dll
  • %ProgramData%\Intel\jli.dll
  • %ProgramFiles%\modifiable\nvml.dll
  • %ProgramData%\ics\nvml.dll

Microsoft Defender Antivirus detects the malware as TrojanDropper:Win64/NeedyMantis and Behavior:Win64/NeedyMantis. Microsoft also published hunting queries that look for these paths in Defender XDR, and for the C2 domain and user agent in both Defender XDR and Microsoft Sentinel.

Cybersecurity

Each query looks back only seven days. Microsoft has not said whether NeedyMantis is still in use, and the files it dated were first seen in October 2025 and May 2026. If run unchanged, the queries would not find events from those months.

A hit on the Poedit path alone does not prove an infection. WinSparkle.dll is also a normal part of Poedit, so compare any file found there with the published hash.

Microsoft recommends several Defender settings: cloud-delivered protection, block at first sight, EDR in block mode, network protection, automatic attack disruption, and two attack surface reduction rules. It also advises checking outbound traffic for connections to the C2 domain, a step that does not need Defender.

Microsoft has not seen NeedyMantis arrive through the tampered DAEMON Tools installers. For those installers, the developer has advised that anyone who downloaded or installed the free DAEMON Tools Lite 12.5.1 during the affected period should uninstall it, run a full system scan, and download version 12.6 from the official website.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.



from The Hacker News https://ift.tt/1zV0ejW
via IFTTT

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy.

The console stores what the malware collects from each phone, including text messages and passwords entered into fake login screens overlaid on banking apps.

Its latest version asks Google's Gemini AI model to estimate each victim's bank balance from those messages and sorts the phones into high-value and mid-value groups.

Nothing in the samples Cleafy analyzed uses the model to move money. Its role is "deciding which victims are worth an operator's time," the company said.

One Console, Three Versions

The malware on victims' phones has changed little since late 2025, Cleafy said. The console behind it has been replaced.

Samples from late 2025 and February 2026 connected to an earlier console named Fisher. Three new versions were in use between April and September 2026, all built from the same code.

The first calls itself BlackCat Remote Control Management. The next two are named Panda Workshop V5 and V6.

Every version is also a build tool. From the console, an operator can build the malware, hide it inside a harmless-looking app, and sign it. The console then publishes the finished app to Amazon S3 or to a web server, without the operator having to touch the hosting setup.

The console can also rebuild the app on a schedule, such as every hour. Each rebuild creates a new file from the same malware, which Cleafy said is aimed at security tools that spot known files by their hash.

The latest version also adds templates for fake download pages, including one called Google Store.

Shell Access in One Click

RatHat reaches phones through text messages and online ads that lead to third-party download sites, Zimperium found earlier this month.

Once installed, the app asks for Accessibility access, which lets an app read the screen and tap for the user. With it, the app enables wireless debugging, reads the pairing code from the screen, and connects to the phone's Android Debug Bridge (ADB), a debugging tool built into Android.

That gives the malware a shell that runs as Android's shell user (UID 2000), outside the permissions granted to the app.

From the console, the operator can use that shell with one click, Cleafy found. A deploy button starts a separate program written in Go that stays reachable through a reverse tunnel, a connection the phone opens to the operator's server.

Pairing with ADB happens automatically, but the Go program runs only after the operator clicks deploy.

That program changes how the operator can watch the screen. Screen capture through the app uses an Android feature that asks the victim for permission and shows a recording icon while it runs.

The Go program instead uses tools called minicap and minitouch to stream the screen and send taps, with no permission prompt and no recording icon.

Neither tool works on Android 14 and later, leaving those phones with the app's own screen capture and permission prompt. Cleafy also described a backup method using a tool called screencap at about 5 frames per second, but did not specify which Android versions it covers.

The Go program keeps running after the victim removes the app, until the phone restarts. Zimperium found that the program can also reinstall the app after it is deleted and turn its Accessibility access back on.

Neither report provides steps to remove the malware completely.

How Widely the Console Is Used

Cleafy found the deployments by searching for the console's page titles and web code. The figure counts console deployments, not infected phones.

Cleafy did not say what counts as one deployment, and neither its report nor Zimperium's gives several victims.

The console limits the number of operator accounts and hides some sections from non-admins. Cleafy said those limits only make sense if the users are customers the developers do not fully trust.

Nearly half of the IP addresses Cleafy observed are on one Singapore-registered network, AS4907.

Gemini on Both Ends

The first console version let operators pick from several AI providers, Cleafy found. It could also send a Telegram alert when a phone's AI score passed a set level.

The latest version works only with Gemini and directs operators to Google AI Studio to get a key.

RatHat also uses Gemini on the phone itself. Its built-in tap instructions are written for specific phone makers' interfaces, Android versions, and languages, so they fail on devices its authors did not anticipate.

When that happens, the malware sends the screen's layout to Gemini and asks where to tap. It calls Gemini straight from the phone, using an API key stored in its own settings.

Cleafy said the feature is used only to keep the wireless debugging setup working.

Android malware has done this before. PromptSpy, which ESET described in February, also sent Gemini the screen layout and followed its tap instructions.

Indicators and Detection

Cleafy listed these indicators for the consoles' command-and-control (C2) servers, download links, and malware samples:

  • Domain: admin.chunhuating[.]best (C2 for Panda Workshop V6, September 2026)
  • Domain: admin.xiongmaocs[.]pics (C2 for Panda Workshop V5, August 2026)
  • IP: 8.231.120[.]246 (C2 for BlackCat, April 2026)
  • Domain: admin.rathat[.]live (C2 for Fisher, December 2025 and February 2026)
  • URL: hxxps://dramaspoolcoa[.]com/en.html (download link, September 2026)
  • URL: hxxps://rathat[.]me/app-release-rat-hat-live.apk (download link, December 2025 and February 2026)
  • MD5: 116346cace7f00ba557034b534d40791 (sample, September 2026)
  • MD5: 8fdc21e25097a46528211274e54330e1 (sample, February 2026)
  • MD5: f83357b2d47c7d38ee53943373961211 (sample, December 2025)

The consoles tend to use web addresses that start with admin., plus adminapi. for the latest version's back end, on cheap top-level domains such as .best, .beer, and .top.

Once the Go program is deployed, the minicap and minitouch files sit in /data/local/tmp under their real names, where a scan can find them. Cleafy said security tools should watch what runs on phones as the shell user, UID 2000.

One of the listed addresses, admin.xiongmaocs[.]pics, also appears in the indicator list Zimperium released with its earlier analysis.



from The Hacker News https://ift.tt/cxrQuS4
via IFTTT

Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild

Executive Summary

Unit 42 is aware of possible zero-day activity against NetScaler devices. Citrix reports that CVE-2026-88771 and CVE-2026-88772 have been exploited in the wild. No further details are currently available about the exploit activity. 

  • CVE-2026-88771 is a remote code execution (RCE) vulnerability that fails to properly validate input and allows an unauthenticated actor to run commands against NetScaler ADC and NetScaler Gateway systems 
  • CVE-2026-88772 is a memory overflow vulnerability that can lead to a remote code execution (RCE) or denial of service (DoS) on the Datagram Transport Layer Security (DTLS) configuration on NetScaler ADC and NetScaler Gateway systems

Both vulnerabilities have a CVSS v4.0 base score of 9.5. 

The Unit 42 Incident Response team can also be engaged to help with a compromise or to provide a proactive assessment to lower your risk.

Vulnerabilities Discussed CVE-2026-88771, CVE-2026-88772

Interim Guidance

Unit 42 recommends that customers update their Citrix software to the latest versions as soon as possible, as well as following the recommendations:

  • Confirm exposure following the “Steps to determine if an appliance meets the CVE preconditions” section of the Citrix Security Advisory for these vulnerabilities
  • Isolate the vulnerable systems from the network
  • Preserve evidence by capturing the following:
    • A NetScaler VPX instance snapshot
    • Logs on remote syslog servers and NetScaler Console
    • A technical support bundle 
    • A packet engine core dump 
  • Hunt for the following:
    • Signs of suspicious administrative sessions
    • Unexpected outbound connections 
    • Unexplained gaps in logging

Note: These are not tactics, techniques and procedures (TTPs) we have observed specifically related to these vulnerabilities. They should be seen as general hunting guidance until more is known about the exploitation activity identified by Citrix in their advisory.  

  • Update and patch to the latest versions 

Note: Updating and patching will not remove access for attackers that have already established persistence within a compromise the network.  

If you think you might have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call: 

  • North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42)
  • UK: +44.20.3743.3660
  • Europe and Middle East: +31.20.299.3130
  • Asia: +65.6983.8730
  • Japan: +81.50.1790.0200
  • Australia: +61.2.4062.7950
  • India: 000 800 050 45107
  • South Korea: +82.080.467.8774


from Unit 42 https://ift.tt/IW8DTNd
via IFTTT

NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

Microsoft Threat Intelligence has identified NeedyMantis, a modular post-compromise malware family observed in a limited number of targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Based on observed activity, NeedyMantis is typically deployed after a threat actor has already established access to a target environment, indicating that the malware is used to maintain long-term access and support follow-on operations.

NeedyMantis activity dates back to at least October 2025. We discovered the malware family while analyzing and pivoting from research and indicators of compromise associated with the DAEMON Tools supply chain compromise, which Kaspersky previously reported on as part of its investigation into the campaign. Observed activity involving NeedyMantis has thus far aligned with activity that Microsoft associates with threat actors operating from China, although Microsoft has not determined whether all observed activity is attributable to the same operator.

While NeedyMantis employs techniques commonly used by modern malware, its architecture combines multiple loaders, custom encrypted file archives, a custom executable file format, and modular components that enable operators to evade analysis and extend functionality through additional modules. These characteristics, combined with its use in targeted intrusions, make NeedyMantis a useful case study for understanding how threat actors establish and maintain long-term access within victim environments.

In this blog, we analyze the NeedyMantis malware framework. We examine its packaging and deployment, custom archive format, loader architecture, command-and-control (C2) communications, and modular design. We also provide indicators of compromise (IOCs), Microsoft Defender detections, and mitigation guidance to help organizations defend against this threat and related activity.

Observed operators and targeting

At the time of writing, Microsoft has observed at least one threat actor using NeedyMantis malware: Storm-3069. Storm-3069 is Microsoft Threat Intelligence’s designator for activity associated with the DAEMON Tools supply chain compromise. While Microsoft assesses the activity originates from China, it has not attributed Storm-3069 to a Chinese nation-state actor. Microsoft identified NeedyMantis through follow-on analysis of indicators associated with Kaspersky’s investigation of the DAEMON Tools compromise.

Microsoft has observed additional NeedyMantis activity beyond Storm-3069’s activity in the DAEMON Tools campaign, indicating that the malware might be used by more than one operator. Observed activity involving NeedyMantis has thus far aligned with activity Microsoft associates with threat actors operating from China, such as targeting that aligns with Chinese interests and the use of selective deployment.

NeedyMantis has been observed in intrusions affecting telecommunications organizations, universities, intergovernmental organizations, medical nonprofits, and government contractors. Combined with the malware’s limited observed deployment and alignment with activity Microsoft associates with China-based threat actors, this victimology suggests NeedyMantis is deployed selectively rather than broadly. However, Microsoft has not determined whether all observed activity is attributable to the same threat actor or whether multiple actors have access to the malware.

Malware packaging and distribution

As previously mentioned, observed activity suggests that the malware is typically deployed after a threat actor has established access to a target environment. As a result, the methods used to gain access before NeedyMantis is deployed may vary across intrusions.

NeedyMantis is composed of multiple components written in C++ and x64 shellcode. The malware starts with a first-stage loader and a file archive. The loader and archive have been found packaged alongside legitimate software, with the first-stage loader–masquerading as a required DLL—being loaded through DLL sideloading.

Some of the open-source, software abused by the malware include: Poedit (translation), curl (data transfer), Vim (text editor), and TightVNC (remote access). Microsoft has also observed NeedyMantis masquerading as Microsoft Office, Broadcom, Intel, and NVIDIA DLL components. The following is a list of some of the DLL path names used by the malware:

  • %ProgramFiles%\Poedit\WinSparkle.dll
  • %ProgramData%\USOShared\libcurl.dll
  • %ProgramData%\VIM\vim64.dll
  • %ProgramData%\TightVNC\VIM\vim64.dll
  • %ProgramData%\office\dbghelp.dll
  • %ProgramData%\broadcom\dbghelp.dll
  • %ProgramData%\Intel\jli.dll
  • %ProgramFiles%\modifiable\nvml.dll
  • %ProgramData%\ics\nvml.dll

The malware’s file archive is named the same as the loader DLL without the extension, for example WinSparkle or libcurl.

In one observed incident, an operator used the Impacket toolkit during hands-on-keyboard activity to copy the legitimate software, malicious DLL, and file archive from a network share and execute it on a targeted device. This activity occurred after the actor had already obtained access to the environment and illustrates one method by which NeedyMantis can be introduced during an intrusion post-compromise.

NeedyMantis is observed during the post-compromise stage of an intrusion after an actor has established access to the target environment. While one known user of the malware, Storm-3069, has been associated with supply chain compromises, Microsoft has not observed NeedyMantis itself being distributed through a supply chain compromise. However, supply chain activity remains one possible means by which an actor could gain the access necessary to deploy the malware.

NeedyMantis architecture and capabilities

First-stage loader

NeedyMantis’ first-stage loader is DLL sideloaded and launched when the legitimate software it is packaged with is run. Its only task is to extract the second-stage loader from its file archive and continue execution there.

In the analyzed sample, the loader DLL was named WinSparkle.dll (SHA-256: e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e) and its file archive was named WinSparkle (SHA-256: 9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef). NeedyMantis spoofed and replaced the WinSparkle software update component of the Poedit translation software.

The loader employs common anti-analysis techniques to hinder analysis, like obfuscating most of its important strings.

A code snippet for x86 architecture manipulating memory addresses and performing data manipulation.
Figure 1. Example obfuscated strings being deobfuscated

This technique is known as obfuscated stack strings because each piece of the string is built up one at a time on the function’s stack. Once built up, it is deobfuscated using various mathematical operations. Most of the obfuscated strings in this loader are Windows DLL and API names. These deobfuscated strings are used to resolve Windows APIs dynamically at runtime.

In addition to obfuscated strings, a lot of the code’s constant values are stored obfuscated as well.

C++ code performing a loop that manipulates a pointer to an integer array, incrementing an element, and then performing a calculation involving pointer arithmetic before a sleep function
Figure 2. Example obfuscated constant value “1032” being deobfuscated

Finally, the loader has two anti-debugger methods: one based on ProcessDebugFlags and the other using ThreadHideFromDebugger.

As noted above, the loader’s main objective is to extract the next stage from its file archive and launch it. In the analyzed sample, the next stage was named encryptbase64.ps1.

Custom file archives

NeedyMantis’ file archives are in an encrypted and compressed custom file format. To get access to the files, the outer layer of the archive is XOR-decoded and RtlDecompressBuffer decompressed. Once decompressed, there are individual file entries. In each file entry, the file’s name is XOR-decoded and its contents are RtlDecompressBuffer decompressed.

The file format’s offsets, XOR keys, and values change from sample to sample.

A hexadecimal data structure depicting a file's header, containing information such as checksums, entry counts, and sizes for various compressed files.
Figure 3. Example output of an archive unpacking tool displaying metadata of the WinSparkle file archive

This archive contains the following 11 files:

  • 7-zip.chm – Legitimate component of 7-Zip
  • 7-zip.dll – Legitimate component of 7-Zip
  • 7-zip32.dll – Legitimate component of 7-Zip
  • 7z.exe – Legitimate component of 7-Zip
  • Disk2vhd.dll – Legitimate Sysinternals component Disk2vhd
  • main.dll – Legitimate Sysinternals component Ctrl2Cap
  • kernel32.dll – Legitimate kernel32.dll
  • encryptbase64.ps1 – Second-stage loader
  • dnsapi.dll – Not a dnsapi.dll, but contains the malware’s configuration
  • ws2_32.dll – Not a ws2_32.dll, but contains a WebSockets based communications DLL
  • msvcrt140.dll – Not a msvcrt140.dll, but contains shellcode to load module DLLs and resolve exports

While this archive contains several legitimate software components, the malware’s functionality is implemented by the remaining files, discussed below.

Other analyzed NeedyMantis file archives have contained different file names and components. An older version of the malware, for example, used a libcurl (SHA-256: c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77) file archive, and it contained only four files:

  • 300.c – Malware’s configuration
  • 300.s – WebSockets-based communications DLL
  • is – Persistence module using Windows Services
  • m.l – Main component

Second-stage loader

In the analyzed sample, encryptbase64.ps1 was the second-stage loader. Despite its .ps1 PowerShell extension, the file contains x64 shellcode. Its purpose is to decode and decompress an embedded binary which is NeedyMantis’ main component.

This loader also has some anti-analysis functionality that differs from stage one. For string decoding, it locates two encoded blocks of data and XOR keys at calculated offsets and then decodes them. The first block, most relevantly, contains a few Windows DLL and API names that are resolved dynamically. The second block, shown below, contains a list of Windows DLL names and Windows API hash values:

A list of hexadecimal numbers depicting a list of Windows DLL names and Windows API hash values.
Figure 4. Decoded Windows API hash values

The component uses a rotate right (ROR) based algorithm with a configurable rotation value (the analyzed sample used value 11) to resolve these Windows API hashes. Figure 5 shows a snippet of Python code reproducing the algorithm:

A snippet of Python code, which includes two function definitions.
`ror(num, count, size)`: and `resolve(func, name)`:
Figure 5. Python snippet of Windows API hashing algorithm

This second-stage loader’s objective is to extract embedded data, XOR-decode it, and then RtlDecompressBuffer decompress it. The location of the encoded data and XOR key are at calculated offsets, which change from sample to sample.

Once decoded the resulting data is a DLL that has been formatted using a custom executable file format. It is a minimized version of a PE file.

Code depicting various metadata and section headers, including offset, base addresses, size, and various attributes for different sections such as '.text', '.rdata', '.data', and '.reloc'.
Figure 6. Example output of custom executable file format to PE file conversion tool

Main component

NeedyMantis’ main component orchestrates C2 communications and handles additional downloaded modules.

It creates a mutex named <username>-<process name>, such as Contoso-Poedit.exe. Like in the first-stage loader, most of the main component’s strings and constant values are stored as obfuscated stack strings.

Configuration

The malware’s configuration was stored in a dnsapi.dll file from the custom file archive. This file name spoofs a Windows networking library. In the sample analyzed, the file contains a 3448-byte binary structure. The structure includes the following fields:

  • 0x00: Unknown (config contained “300”, but components also reference “400”)
  • 0x1c: Communication component name (ws2_32.dll)
  • 0x128: C2 port (443)
  • 0x12c: C2 host (corp.tripswithengine[.]com)
  • 0x334: C2 URI (/library/zip/)
  • 0x53C: WinHttpOpen AccessType (0)
  • 0x954: Proxy username (not set)
  • 0xB5C: Proxy password (not set)
  • 0xD64: Sleep time related (300)
  • 0xD68: Sleep time related (300)

Communications DLL

As referenced in the configuration, NeedyMantis makes use of a communication component called ws2_32.dll. This component is also stored in the custom file archive. Like the config file, the file name spoofs a Windows networking library.

This communications DLL has one export named SystemInfo. As shown below in Figure 7, SystemInfo exposes 10 functions for the main component to initiate and maintain a WebSockets connection with the C2:

A sequence of function declarations for a communication system, including open, close, connect, send, receive, and placeholder functions.
Figure 7. Communications DLL API functions

The library uses WinINet APIs for WebSockets. It also has a hard-coded user-agent of firefox/21.0.

We have also spotted a second version of the communications DLL in a file archive. It implements the same communications API but uses Libwebsockets (LWS) instead of WinINet.

Command and control

The initial C2 beacon is an HTTPS GET request, similar to Figure 8 below:

An HTTP request for a ZIP file in a web browser, specifying various cache control and connection settings.
Figure 8. Initial C2 HTTPS GET request

The Set-Cookie header contains system information. The header value can be Base64-decoded and RtlDecompressBuffer decompressed. Once decompressed it contains a JSON object. The key values are:

  • c – Computer name
  • u – Username
  • o – Base64-encoded data, once decoded it contains line separated “
    • p – Process list

The connection is then converted to WebSockets and a binary C2 protocol is continued. The binary protocol is separated into a header and optional data components. The 44-byte header includes the following fields:

  • 0x00: 16-byte XOR key
  • 0x10: Uncompressed data length
  • 0x14: Compressed data length
  • 0x18: Command number
  • 0x28: Data length
  • 0x2c: Optional data

A 16-byte random XOR key is generated and the header is XOR-encoded, starting at offset 0x18. If there is any data, it is compressed with RtlCompressBuffer and optionally encrypted with RC4.

The initial messages of the binary protocol are a key exchange with the C2 server. The protocol is performed as such:

  • 32-bytes are received from the C2 server, but then ignored
  • A 1024-byte random buffer is created
  • The first 32-bytes of this random buffer are used as the RC4 key for further communications
  • A 256-byte buffer is created that starts with google.com followed by random bytes
  • The 256-byte buffer is RC4 encrypted
  • A random length between 292 and 1282 is picked
  • The C2 protocol message data is structured as such:
    • 0x00: The random length
    • 0x04: RC4 encrypted google.com buffer
    • 0x104: The random 1024-byte buffer used to create the RC4 key (at least 32 bytes of it)
  • This message data is compressed, but not RC4 encrypted
  • A random command number between 1 and 45 is chosen
  • The C2 server uses the buffer at offset 0x104 to recreate the RC4 key and presumably checks the RC4 encrypted google.com buffer
  • The server sends back the random command number as an acknowledgement

Commands

The main component only has a handful of commands. Commands sent to the C2 include:

  • 1110 – Sends computer name and username
  • 1112 – Sends a hard-coded identifier (like 20001)
  • 1150 – Keep alive

Commands received from the C2 include:

  • 1020 – Load module
  • 1030 – Unload module
  • 1050 / 1150 – Dispatch data to module
  • 1070 – Turn off active flags

The main component’s load, unload, and data dispatch commands show that NeedyMantis can extend its functionality through additional modules, but the capabilities of those modules remain unconfirmed.

Mitigation and protection guidance

Microsoft recommends the following mitigations to reduce the impact of this threat.

You can assess how an attack surface reduction rule might impact your network by opening the security recommendation for that rule in threat and vulnerability management. In the recommendation details pane, check the user impact to determine what percentage of your devices can accept a new policy enabling the rule in blocking mode without adverse impact to user productivity.

Microsoft Defender detections

Microsoft Defender customers can refer to the list of applicable detections below. Microsoft Defender coordinates detection, prevention, investigation, and response across endpoints, identities, email, apps to provide integrated protection against attacks like the threat discussed in this blog.

Tactic Observed activity Microsoft Defender coverage
ExecutionShellcode loading, DLL sideloading, decryption, and decompressionMicrosoft Defender for Endpoint
– Suspicious DLL loaded
– An executable file loaded an unexpected DLL file
– Suspicious decode command

Microsoft Defender Antivirus
– TrojanDropper:Win64/NeedyMantis
ExecutionHands-on-keyboard leveraging Impacket tool for follow-on activityMicrosoft Defender for Endpoint
– Ongoing hands-on-keyboard attack via Impacket toolkit
– Impacket toolkit
– Impacket module execution

Microsoft Defender Antivirus
– HackTool:Win32/Impacket
ExecutionStorm-3069 threat actor TTPsMicrosoft Defender for Endpoint
– Suspicious activity linked to an emerging threat actor has been detected
Command and controlNetwork connectivity to NeedyMantis infrastructureMicrosoft Defender Antivirus
– Behavior:Win64/NeedyMantis

Microsoft Security Copilot

Microsoft Security Copilot is embedded in Microsoft Defender and provides security teams with AI-powered capabilities to summarize incidents, analyze files and scripts, summarize identities, use guided responses, and generate device summaries, hunting queries, and incident reports.

Customers can also deploy AI agents, including the following Microsoft Security Copilot agents, to perform security tasks efficiently:

Security Copilot is also available as a standalone experience where customers can perform specific security-related tasks, such as incident investigation, user analysis, and vulnerability impact assessment. In addition, Security Copilot offers developer scenarios that allow customers to build, test, publish, and integrate AI agents and plugins to meet unique security needs.

Threat intelligence reports

Microsoft Defender XDR customers can use the following threat analytics reports in the Defender portal (requires license for at least one Defender XDR product) to get the most up-to-date information about the threat actor, malicious activity, and techniques discussed in this blog. These reports provide the intelligence, protection information, and recommended actions to prevent, mitigate, or respond to associated threats found in customer environments.

Microsoft Security Copilot customers can also use the Microsoft Security Copilot integration in Microsoft Defender Threat Intelligence, either in the Security Copilot standalone portal or in the embedded experience in the Microsoft Defender portal to get more information about this malware and associated activity.

Hunting queries

Microsoft Defender XDR

Microsoft Defender XDR customers can run the following advanced hunting queries to find related activity in their networks:

NeedyMantis masquerading as software

A listing of legitimate, unmodified application folders, along with malicious replacement DLL filenames sideloaded by NeedyMantis.

DeviceFileEvents
| where Timestamp > ago(7d)
| where (
    (FolderPath matches regex @"^[A-Za-z]:\\Program Files\\Poedit" and FileName == "WinSparkle.dll")
    or (FolderPath matches regex @"^[A-Za-z]:\\Program Files \(x86\)\\Poedit" and FileName == "WinSparkle.dll")
    or (FolderPath matches regex @"^[A-Za-z]:\\ProgramData\\USOShared" and FileName == "libcurl.dll")
    or (FolderPath matches regex @"^[A-Za-z]:\\ProgramData\\VIM" and FileName == "vim64.dll")
    or (FolderPath matches regex @"^[A-Za-z]:\\ProgramData\\TightVNC\\VIM" and FileName == "vim64.dll")
    or (FolderPath matches regex @"^[A-Za-z]:\\ProgramData\\office" and FileName == "dbghelp.dll")
    or (FolderPath matches regex @"^[A-Za-z]:\\ProgramData\\broadcom" and FileName == "dbghelp.dll")
    or (FolderPath matches regex @"^[A-Za-z]:\\ProgramData\\Intel" and FileName == "jli.dll")
    or (FolderPath matches regex @"^[A-Za-z]:\\Program Files\\modifiable" and FileName == "nvml.dll")
    or (FolderPath matches regex @"^[A-Za-z]:\\Program Files \(x86\)\\modifiable" and FileName == "nvml.dll")
    or (FolderPath matches regex @"^[A-Za-z]:\\ProgramData\\ics" and FileName == "nvml.dll")
)
| project Timestamp, DeviceId, DeviceName, ActionType, FolderPath, FileName,
          SHA1, SHA256, MD5,
          InitiatingProcessAccountDomain, InitiatingProcessAccountName, InitiatingProcessAccountSid,
          InitiatingProcessAccountUpn,
          InitiatingProcessMD5, InitiatingProcessSHA1, InitiatingProcessSHA256,
          InitiatingProcessFolderPath, InitiatingProcessFileName, InitiatingProcessCommandLine,
          InitiatingProcessCreationTime,
          ReportId, TenantId

NeedyMantis C2

This query identifies connectivity to the NeedyMantis command and control site for this activity.

search in (DeviceNetworkEvents, EmailUrlInfo, UrlClickEvents, DeviceEvents, DeviceFileEvents, DeviceProcessEvents)
  "corp.tripswithengine.com"
| where Timestamp > ago(7d)
| extend SourceTable = $table
| project Timestamp,
          DeviceName,
          InitiatingProcessAccountName,
          InitiatingProcessAccountUpn,
          AccountName,
          AccountUpn,
          RemoteIP,
          LocalIP,
          IPAddress,
          RemoteUrl,
          Url,
          UrlDomain,
          FileOriginUrl,
          FileOriginReferrerUrl,
          FileOriginIP,
          ProcessCommandLine,
          InitiatingProcessCommandLine,
          InitiatingProcessFileName,
          FileName,
          FolderPath,
          NetworkMessageId,
          SourceTable

NeedyMantis communications DLL hard-coded user-agent

Identify connectivity utilizing the NeedyMantis hard-coded user-agent.

search in (DeviceNetworkEvents, DeviceEvents, UrlClickEvents, EmailUrlInfo)
  "Firefox/21.0"
| where Timestamp > ago(7d)
| extend SourceTable = $table
| project Timestamp,
          DeviceName = iff(isnull(DeviceName), "", DeviceName),
          AccountUpn = coalesce(InitiatingProcessAccountUpn, AccountUpn, ""),
          AccountName = coalesce(InitiatingProcessAccountName, AccountName, ""),
          RemoteIP = coalesce(RemoteIP, IPAddress, ""),
          Url = coalesce(RemoteUrl, Url, ""),
          UserAgent = AdditionalFields,
          SourceTable

Microsoft Sentinel

Microsoft Sentinel customers can use the TI Mapping analytics (a series of analytics all prefixed with ‘TI map’) to automatically match the malicious domain indicators mentioned in this blog post with data in their workspace. If the TI Map analytics are not currently deployed, customers can install the Threat Intelligence solution from the Microsoft Sentinel Content Hub to have the analytics rule deployed in their Sentinel workspace.

NeedyMantis C2

This query identifies connectivity to the NeedyMantis command and control site for this activity.

search in (CommonSecurityLog, SecurityEvent, AzureDiagnostics)
  "corp.tripswithengine.com"
| where TimeGenerated > ago(7d)
| project TimeGenerated,
          DeviceName,
          Computer,
          SourceIP,
          SourcePort,
          SourceUserName,
          DestinationIP,
          DestinationPort,
          DestinationHostName,
          DestinationDnsDomain,
          RequestURL,
          ProcessName,
          DestinationUserName,
          SourceHostName,
          Message,
          $table

NeedyMantis communications DLL hard-code user-agent

Identify connectivity utilizing the NeedyMantis hard-code user-agent.

CommonSecurityLog
| where TimeGenerated > ago(7d)
| where RequestClientApplication contains "Firefox/21.0" or Message contains "Firefox/21.0"
| project TimeGenerated, DeviceName, SourceUserName, SourceIP, DestinationIP, RequestURL, RequestClientApplication

Indicators of compromise

IndicatorTypeDescriptionFirst seenLast seen
e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e SHA-256First-stage loader WinSparkle.dll 2026-05-21 2026-05-21
9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077efSHA-256Custom file archive WinSparkle 2026-05-23 2026-05-23
c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77SHA-256Custom file archive libcurl2025-10-032025-10-03
corp.tripswithengine[.]comHost nameC2 host name

References

Learn more

For the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To get notified about new publications and to join discussions on social media, follow us on LinkedIn, X (formerly Twitter), and Bluesky.

To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the Microsoft Threat Intelligence podcast.

The post NeedyMantis: Unpacking a post-compromise malware family used in targeted operations appeared first on Microsoft Security Blog.



from Microsoft Security Blog https://ift.tt/RbCHXTc
via IFTTT

⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface.

Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing exotic. Mostly things nobody expected to matter anymore.

Here’s the full recap of what mattered this week.

⚡ Threat of the Week

Citrix Warns of Actively Exploited NetScaler ADC and Gateway Flaws — Citrix released patches to address multiple vulnerabilities, including CVE-2026-88771 and CVE-2026-88772, that have come under active exploitation. CVE-2026-88771 is an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands, while successful exploitation of CVE-2026-88772 could allow for remote code execution or denial-of-service. CISA said "threat actors are actively exploiting these vulnerabilities globally," urging federal agencies to apply patches by Wednesday.

🔔 Top News

  • Bitget Resumes Withdrawals After Hack — Cryptocurrency exchange Bitget resumed Bitcoin withdrawals in phases after suspected North Korean hackers breached its systems last week and stole over $387 million. "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," Bitget said. "Bitget's cold wallets and the overwhelming majority of platform assets remain secure and unaffected." According to a real-time fund tracing dashboard published by Coindesk, Circle and Tether have frozen stablecoins worth $339,100 linked to the hack.
  • PamStealer Adds Live C2 Payload Decryption — A new version of PamStealer has been found to incorporate a new anti-analysis trick that ensures the main payload can only be recovered using a server-side decryption chain. The latest artifacts continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material directly in the JXA source, it now fetches a purpose-built decryption utility and completes a key exchange with the server before the payload can be unwrapped," Jamf said. "Without the server's cooperation, the payload cannot be recovered statically."
  • Placeholder Domain Found References in ~1.7K Repos — The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. "third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays," Manifold Security said. "Unlike 'example[.]com,' third-party[.]com is not IANA-reserved. Anyone could register it, and someone did. Every doc, test, and skill that hard-coded it now points readers at attacker infrastructure." As of writing, the domain has been marked as malicious and unsafe on both VirusTotal and Google's Safe Browsing list. Manifold also identified 13 more placeholder domains that are not IANA-reserved, with two of them – yoursite[.]com and your-domain[.]com – serving scams and scareware to macOS visitors and an ordinary parking page to other users.
  • UNK_CondorFiltration Abuses TeamFiltration in New Campaign — An active TeamFiltration campaign codenamed UNK_CondorFiltration has targeted over 5,700 accounts across 28 Microsoft 365 tenants. The activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses. "The campaign compromised 7 accounts – all of which were unmanaged functional or service accounts rather than individual employee accounts – highlighting a critical exposure gap around forgotten, non-human identities carrying default or unrotated passwords and no MFA," Proofpoint said. The activity took place over three waves from late July to August 2026.
  • EvilTokens Taken Down in Law Enforcement Action — A coalition of law enforcement and private-sector tech companies led by Microsoft dismantled the EvilTokens phishing service, arresting two suspected website admins, Felix Utomi and Waidi Segun Adams, taking down more than 50 websites, and notifying victims of compromised email accounts. Per Coinbase, the EvilTokens operators were said to be working on expanding the kit to target Gmail and Okta accounts at the time of the takedown. Microsoft attributes the development and support of the platform to Storm-2992. EvilTokens is the latest example of professionalization of cybercrime, allowing bad actors to mount phishing campaigns with little effort and at scale. EvilTokens' notable feature was the device code phishing flow, which took advantage of security gaps in devices that cannot support standard sign-in methods like smart TVs, printers, conferencing tools, and Teams devices. In these attacks, victims are sent a short code and are told to enter that code into a phishing page to complete authentication. The important aspect here is that instead of a legitimate device requesting access, the threat actor initiates the flow and provides the user with a code through a phishing lure. When the code is entered, victims unknowingly authorize the cybercriminals' session and grant them access without ever handing over their password.
  • OpenAI Linked to More Website Hacks — AI research lab Transluce found three instances between May and June 2026 in which OpenAI's agents resorted to hacking when traditional methods failed. This included an attempt on an Australian government public health website. "Notably, the agents did this while attempting mundane data retrieval tasks which were not cyber-related," Transluce said. "This traffic goes back at least to March 6, 2026 and extends as recently as September 16, 2026, suggesting agents may still be exploiting these services to bypass restrictions."

‎️‍🔥 Trending CVEs

Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.

Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-77179 (Docker), CVE-2026-93485, CVE-2026-87902 (WordPress), CVE-2026-89775 (Linux kernel), CVE-2026-93616, CVE-2026-85102 (Check Point), CVE-2026-93952 (Arista VeloCloud Orchestrator), CVE-2026-90898 (Bifrost), CVE-2026-86555, CVE-2026-86554, CVE-2026-86553, CVE-2026-86552 (ZTE H188A/H288A firmware), CVE-2026-94545 (Next.js), CVE-2026-94127 (F5 BIG-IP Access Policy Manager), CVE-2026-86296, CVE-2026-86510 (D-Link DIR-822A), CVE-2026-87900, CVE-2026-87899, CVE-2026-68490 (cPanel), CVE-2026-82356 (Imprivata Enterprise Access Management), CVE-2026-86867 (Cinnamon Kotaemon), CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, CVE-2026-75698, CVE-2026-75745, CVE-2026-81995, CVE-2026-82000 (Adobe), CVE-2026-95350, CVE-2026-95357, CVE-2026-95339, CVE-2026-95281, CVE-2026-95313, CVE-2026-95349, CVE-2026-95284, CVE-2026-95322, CVE-2026-95329, CVE-2026-95356, CVE-2026-95310 (Google Chrome), CVE-2024-0244 (Canon MF753Cdw), CVE-2026-28324, CVE-2026-28325 (SolarWinds Observability Self-Hosted), CVE-2026-97359, CVE-2026-97360 (HFS2), CVE-2026-96560 (LightLLM), CVE-2026-80145, CVE-2026-80144, CVE-2026-80143 (Lantronix), CVE-2026-82987, CVE-2026-82988, CVE-2026-82989 (ViewSonic vCast), CVE-2026-75907 (Norwegian Cruise Line door access controller), CVE-2026-18311, CVE-2026-18312, CVE-2026-18320 (Readwise Reader for Android), CVE-2026-88771, and CVE-2026-88772 (Citrix NetScaler ADC and Gateway).

🎥 Cybersecurity Webinars

📰 Around the Cyber World

  • Clop Gang Moves Site After ShinyHunters Hack — The Clop ransomware gang moved its data leak site to a new Tor address after its previous server was compromised and defaced by ShinyHunters through an unpatched Grav CMS flaw that's now assessed to be an unauthenticated path traversal vulnerability (CVE-2026-42608). The vulnerability was patched by Grav in April 2026. In a statement shared with Bleeping Computer, Clop denied having any relationship or ongoing negotiations with ShinyHunters. "We do not know them, we have never worked with them, and at the moment we are not in contact with them; furthermore, we have not provided them with any information, nor will we do so – either now or in the future," the group was quoted as saying. The development comes in the aftermath of ShinyHunters seizing the FBI's FBIjobs.gov portal by what it said was a new zero-day in Oracle PeopleSoft.
  • Konni Targets Ukraine with Malicious LNK Lures — The North Korean threat group known as Konni has been observed using ZIP archives with malicious LNK files masquerading as PDF documents as lures in spear-phishing attacks targeting Ukraine-focused individuals and organizations to deliver a malware called VelvetCake as part of a campaign codenamed Operation Conflict Compass. The LNK file launches a VBScript that establishes persistence via a scheduled task, and triggers a PowerShell script to run every minute. The invoked PowerShell payload functions as a modular downloader designed to fetch and execute secondary server-side scripts. "VelvetCake embeds no fixed post-exploitation capability set locally. It operates as a lightweight task runner that continuously retrieves and executes server-side PowerShell modules, allowing operators to modify functionality without redeploying the core payload," SOCRadar said. "The campaign likely aimed to gather intelligence on the trajectory of the Russian invasion to gauge the medium-term outlook of the war."
  • Kimsuky Conducts Git-Based C2 Attacks — In more North Korea-related malicious activity, the Kimsuky group has resorted to conducting Git-based C2 attacks through malicious LNK files contained within ZIP archives. The activity has been dubbed Operation GitPower. The LNK files use filenames disguised as documents related to financial and corporate operations, including fund disbursement, insurance premiums, interest payments, policy funds, certificate renewal, store master data, customer documents, and Visa payments. These documents are said to have been mass-produced using AI models, spotlighting a trend where the threat actor has used local large language models (LLMs) using Ollama, GPT4All, and Msty to prepare attacks and create decoys. The LNK files serve as delivery vectors for follow-on PowerShell commands retrieved from GitHub Raw Content paths using a GitHub PAT. Select variants have also been observed using Pastebin as an alternative channel. The PowerShell code sets persistence, exfiltrates system information to GitHub, and takes steps to erase itself and the PowerShell command history file.
  • CISA Flags TeamCity Flaw as Exploited in Ransomware Attacks — CISA confirmed that ransomware gangs are exploiting a critical JetBrains TeamCity vulnerability patched in July. The flaw, CVE-2026-63077, is a critical authentication bypass vulnerability that lets attackers with HTTP(S) access execute arbitrary operating system commands. "An unauthenticated attacker could exploit the vulnerability via the TeamCity agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process," JetBrains said. It's currently not known which ransomware group is behind the exploitation activity.
  • DeepMind Gives Private AI Compute a Secure, Server-Side Memory — Google has announced plans to bring a private, server-side memory to its Private AI Compute platform, giving AI systems long-term continuity across devices without sacrificing privacy. "With this new technical capability, a new persistent memory layer will be able to function like a secure digital vault in the cloud," Google DeepMind said. "Under this model, the information needed to assist you is sealed within dedicated, encrypted storage, while the cryptographic keys required to unlock it are held exclusively on your personal devices — ensuring your data is inaccessible to anyone else, even Google."
  • SectopRAT Hides Inside Legitimate Application — A new campaign has been observed delivering SectopRAT by concealing it within a legitimate program developed by an Italian digital-audio company. It's suspected that the operators added the malware after the application was installed on customer systems rather than compromising the vendor itself. "SectopRAT (also known as ArechClient2) is a .NET-based remote access trojan (RAT) that provides a range of functions through multiple control commands," Fortinet said. "These include collecting sensitive data from the victim’s device, capturing screens, remotely managing processes and files, controlling bots, and other forms of remote device management."
  • Armenian National Sentenced to 2 Years for Ryuk Ransomware Attacks — Karen Serobovich Vardanyan, 34, who was extradited from Ukraine to the U.S. in June 2025, has been sentenced to 24 months in federal prison and 3 years' supervised release. In July 2026, Vardanyan pleaded guilty to conspiracy and computer fraud for his role in Ryuk ransomware attacks and an extortion conspiracy targeting companies across the U.S. "Between November 2019 through April 2020, Vardanyan illegally accessed computer networks of victim companies to deploy Ryuk ransomware on compromised servers and workstations," the U.S. Justice Department said. "Ryuk ransomware is a type of malicious software designed to encrypt data on a victim's computer or network and prevents the victim from accessing the encrypted files until a ransom is paid. Vardanyan worked with his co-conspirators to attack a company in Michigan that paid 200 bitcoin, or over $1.1 million at the time of payment, to restore access to their network. They also attacked a company in Wilsonville, Oregon, and in February 2020 attacked a school in Texas." Vardanyan and his co-conspirators are said to have illegally accessed computer networks of victim companies and deployed ransomware on hundreds of compromised servers and workstations, receiving over $15 million in illicit proceeds at that time. Vardanyan has also been ordered to pay over $1.21 million in restitution.
  • Scattered Spider Member Gets 45-Month Prison Sentence for Cybercrime Spree — Ahmed Hossam Eldin Elbadawy, of Texas, who admitted to being a member of the notorious cybercrime group Scattered Spider, has been sentenced to 45 months in prison. Following that, Elbadawy will face a three-year parole and is prohibited "from using privacy-based blockchain virtual currencies" without prior approval. Elbadawy was charged in November 2024 along with four other defendants.
  • Using Rogue External MFA Provider to Steal Passwords — Varonis has demonstrated a new attack technique called TrustSink which turns a rogue external MFA provider into a "persistent credential trap" within a legitimate sign-in flow. "An attacker with high privileges can register a rogue External Authentication Method (EAM) and place a convincing password page inside the legitimate sign-in flow," Varonis said. "The page captures the password in plaintext while the provider returns a valid signed token, completing the login without an error. Resetting a captured password did not remove the rogue provider. It remained in the authentication flow and captured the replacement password at the user's next sign-in." TrustSink builds on previous research by security researcher Dirk-Jan Mollema, who found that a rogue registered EAM provider can be used to bypass MFA by returning a signed JWT without performing a real authentication check.
  • New x47.c Botnet Drains AI API Credits — A previously undocumented Windows botnet dubbed x47.c has been advertised as capable of supporting 18 DDoS attack methods, browser credential theft, SOCKS5 proxies, and an AI module that uses SpaceXAI Grok to establish persistence on infected machines based on the current state. It's sold by a threat actor named WraithTools for a $200 base package with a $150 DDoS add-on. The entire toolset costs $950. "One of the advertised methods, 'AI API drain,' is designed to exhaust a victim's paid AI credits," Qrator Research Labs said. "Using a valid API key, an operator can send repeated requests that consume the account’s balance or increase its bill. The AI drain command starts with a valid API key for the account being targeted. Because those requests go straight to the provider, they do not need to pass through the victim’s application. The website can remain reachable while the account behind its AI features runs out of credits. If the provider rejects further requests once the account balance is exhausted or an enforced limit is reached, legitimate users lose access to those features."
  • Hundreds of Leaked GitHub App Keys Still Active — A new analysis from GitGuardian has found that hundreds of GitHub App private keys leaked in public code still work. From over 500,000 exposed RSA keys, 474 have been found to authenticate as 440 distinct Apps on GitHub's API. "72% of the compromised Apps had some content permissions, meaning that they could access private repositories of the organizations that use them," GitGuardian said. " 207 of them have content write permissions and can modify those repositories. Even worse, 44 Apps have organization administration privileges, 40 can administer self-hosted runners, and 98 can control workflows. Those permissions could allow a complete takeover of the target organization, or code execution on its internal infrastructure, with or without further supply-chain compromise."

Conclusion

The common thread this week was not sophistication. It was neglect. Forgotten accounts, stale assumptions, old flaws, exposed services, and tooling that keeps getting more capable faster than the controls around it.

That is usually how these weeks land: the dramatic stories get attention, but the quieter failures keep doing the real work underneath. The patch nobody rushed, the identity nobody owned, the placeholder nobody questioned, the service nobody hardened.

That’s it for this week. Patch the obvious stuff, check the forgotten stuff, and assume somebody else already noticed it too.



from The Hacker News https://ift.tt/njru3PN
via IFTTT

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent.

"The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39-line prompt directs it to execute tasks received through Telegram, maintain persistence, and collect credentials."

At a high level, the botnet breaks into Docker daemons exposed without authentication on port 2375 and scans neighboring networks every five minutes to propagate further. On each host, it installs Hermes Agent with instructions to follow operators' Telegram commands.

The cybersecurity company said it found the operation through an unauthenticated Docker registry that's been publicly accessible since May 2026. The staged data has been found to include details of the botnet and a separate campaign that distributed trojanized cryptocurrency wallet apps.

CARBONATO possesses worm-like capabilities in that it can spread to other hosts with unauthenticated Docker daemons. Once a host is discovered, it launches a privileged container and run commands on the underlying system.

"It uses a privileged​ ​container​ ​to​ ​run​ ​commands​ ​on​ ​each​ ​host,​ ​establishes​ ​persistence and remote access, then scans nearby networks for further Docker daemons," ThreatDown said. "Hermes​​ Agent​​ gives ​​the​ ​operators​​ a​​ Telegram​​ interface ​​to ​​send ​​tasks ​​to ​​compromised​​ hosts,​​ and​​ its persona names AI API keys and other credentials as the priority."

All of this is achieved by means of a shell script that launches a reverse SSH tunnel​​ from the victim to a relay located in Costa Rica, after which it installs an SSH server with the operators' key and reports the new deployment through Telegram with the container details.

The malware also takes steps to evade detection by masquerading as a system component and establishes persistence using cron jobs and watchdog scripts that ensure the implant is re-launched if the malicious artifacts are removed.

With the persistence set up, the next step involves deploying the Hermes Agent and overwriting its SOUL.md persona file with a custom prompt that asks the AI tool to assume the role of a "senior hacker, pentester, and exploit developer" named GH0ST and instructs it to "maintain persistence, respond over Telegram, and execute any operation the operator asks" without "moral or ethical restrictions."

The agent then enters into an interactive command loop that interprets incoming tasks through Telegram and forwards them to the appropriate large language model (LLM) gateway. The model then writes the terminal commands that are executed by the agent and returns the results back to the threat actor over the messaging platform.

The activity has not been attributed to any known threat actor or group. Language, timezone, and infrastructure clues indicate that the operators are based in Costa Rica.

Rising Attack-Chain Automation

The disclosure comes amid growing threat actor use of AI tools and models to automate various aspects of the cyber attack lifecycle and offload offensive work.

In July 2026, Palo Alto Networks linked a China-based threat actor dubbed "knaithe" and "KnYuan" to an AI-enabled hacking campaign that leveraged DeepSeek, via the Hermes Agent framework configured to accept instructions over Telegram, to enumerate targets, source exploit tools, and launch attacks without human intervention.

That same month, Hunt.io also highlighted another operation in which attackers used Hermes Agent in unattended "YOLO" mode to target Thailand's Ministry of Finance (MOF), ultimately breaching multiple systems within the network.

"The combination is what stands apart: an AI agent coordinating the work, a cross-platform implant holding access, and scripts written for this specific target," Hunt.io said. "Together they describe an operator who invested significant preparation into penetrating a single government target."

As recently as last week, Gambit Security said it identified a Chinese-speaking financially motivated operator running three open-source AI harnesses against hundreds of online retailers, compromising at least 27 companies, stealing over 600,000 credit card details from two entities, and injecting skimmer scripts into five online stores.

The activity, which has been ongoing since July 2026, uses AI at all stages of the attack, with results of one informing the next -

  • Strix, an AI penetration testing tool for vulnerability hunting
  • Cairn, an autonomous penetration testing engine for autonomous end-to-end exploitation by launching 105 attack projects between September 10 and 15, 2026, using DeepSeek v4.1 Flash
  • Hermes, for orchestration, post-exploitation, tactical guidance, and directing the malicious activity using Anthropic Claude Opus 4.6

The threat actor is said to have loaded the Chinese system persona titled "SOUL - Red Team Operator" onto Hermes Agent and carried out the attack largely without any human involvement, and erased the card data from the victims' Magento database once the data had been exfiltrated.

The stolen card details correspond to victims from the U.S., the U.A.E., Saudi Arabia, the U.K., New Zealand, Ireland, Singapore, Kuwait, Australia, and Hong Kong.

"At very low cost, the AI tools demonstrated a level of patience, persistence, and creativity that most human attackers would be unlikely to sustain in this kind of attack, and achieved far greater results, far faster," security researcher Eyal Sela said. "Organizations must adapt to a reality where attacks are significantly faster and more comprehensive by shifting to a resilience-first mentality and a security stack that matches the AI speed."

The findings also coincide with the discovery of a new Go-based Windows implant called CLOSEDQUORUM that can query up to four LLM providers, namely DeepSeek, Alibaba Qwen, Mistral, and Google Gemini (and in this order), to autonomously determine the next course of action during the post-compromise stage of an attack.

The voting system allows the malware to take a predefined set of actions based on the winning decision, thereby automating the command-and-control (C2) chain and eliminating the need for continuous attacker commands. These actions include credential theft, shellcode injection using process hollowing or Early Bird APC injection, persistence, and likely lateral movement.

"CLOSEDQUORUM appears to operate as an operator-configured service rather than malware deployed directly by its developer," Cisco Talos said. "DeepSeek holds the deciding vote in any tie. If DeepSeek failed and isn't in the quorum, Qwen's vote is the deciding vote, and so on down the priority order. The tie behavior is fully deterministic and biased toward DeepSeek."



from The Hacker News https://ift.tt/08sGFjT
via IFTTT