NeedyMantis Is Hiding Behind Poedit, curl, Vim and TightVNC

Microsoft found NeedyMantis hiding beside legitimate software in targeted intrusions. The real hunt starts before the backdoor appears.

Microsoft found NeedyMantis hiding beside legitimate software in targeted intrusions. The real hunt starts before the backdoor appears.

Mantax Otax combines ransom demands with screen monitoring and message theft. Newer Android limits broad file encryption, but not every other risk.

Microsoft says a China-focused campaign is rebuilding malicious installers between downloads, making familiar names and file hashes unreliable clues.

A multinational operation redirected Sality's peer-to-peer command traffic into sinkholes after two decades and more than 11 million linked IP addresses.
Nineteen Chrome and Edge extensions delivered wallet-draining and credential-stealing modules, including five legitimate tools weaponised after ownership changes.

A fake verification prompt led to DLL sideloading, Active Directory reconnaissance and a reverse tunnel that turned one Windows endpoint into an internal network pivot.

Cruciferra combines ClickFix delivery, a signed vulnerable driver, signed Microsoft binaries and process hollowing to disable endpoint security and deploy an infostealer.

AnonyMousKIT combines stolen-device data, phishing pages and low-cost AI voice agents to obtain the credentials needed to disable Activation Lock.

Attackers used npm packages as storage for fake verification pages rendered through trusted mirrors, turning legitimate CDN domains into phishing infrastructure.

ToxicPanda 2.0 abuses VPN permission to cut off Google Play, then automates Android wireless debugging to obtain shell-level capability. The chain shows how legitimate platform functions can become a post-compromise control path.