All Posts
Anomali Cyber Watch
1
min read

Anomali Cyber Watch: NeedyMantis, Warlock, Cloud Risks and more

Published on
October 6, 2026
Table of Contents

At a Glance

Attack Patterns
68
Hijack Execution Flow: Dll Side-Loading
2
Create or Modify System Process: Windows Service
2
System Owner/User Discovery
2
Lateral Tool Transfer
2
Application Layer Protocol: Web Protocols
2
Target Regions
3
Americas: 66.7% (2)Europe: 33.3% (1)Americas: 66.7% (2)Europe: 33.3% (1)
Hover over the chart to see data
Industries
11
Education: 27.3% (3)Telecommunications: 18.2% (2)Infrastructure / Water: 9.1% (1)Government / Government Regional: 9.1% (1)Government: 9.1% (1)Other: 27.3% (3)Education: 27.3% (3)Telecommunications: 18.2% (2)Infrastructure / Water: 9.1% (1)Government / Government Regional: 9.1% (1)Government: 9.1% (1)Other: 27.3% (3)
Hover over the chart to see data
* Frequency counts reflect mentions across collected reports
Story #1  |  September 28, 2026

NeedyMantis Malware Selectively Deployed in Targeted Operations Linked to China-Based Threat Actors

▶ expand
Telecommunications � Education
NeedyMantis is a modular post-compromise malware framework used to maintain long-term access and support follow-on operations, typically deployed after attackers have established a foothold in a target environment. Active since at least October 2025, it has been observed in targeted intrusions against telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. The malware uses dynamic link library (DLL) sideloading, bundling a malicious DLL with a legitimate application so Windows loads it when the program runs. Legitimate applications abused include Poedit, curl, Vim, and TightVNC. Two loader stages follow, each applying obfuscation and anti-analysis techniques to resist examination, before the main component activates. That component sends an initial HTTPS beacon to its command-and-control (C2) server transmitting encoded system information, then upgrades to a WebSocket session using a binary protocol protected by XOR encoding, compression, and optional RC4 encryption. A hard-coded user agent of firefox/21.0 provides a useful network hunting indicator. The main component supports loading and unloading additional modules at runtime, though their specific capabilities remain unconfirmed. Observed activity, spanning at least one confirmed operator and potentially others, aligns with targeting patterns associated with China-based threat actors, though no nation-state attribution has been established.
Analyst Comment
The selectivity here is the most important signal. NeedyMantis has been observed in a limited number of targeted intrusions, suggesting operators may reserve it for environments where maintaining access has operational value. Where it surfaces, initial access will typically have already occurred, with the malware used to sustain that position and support follow-on operations. Organizations within the documented sectors, including government contractors, should prioritize active hunting alongside existing alerting and detection coverage. Defenders using the published hunting queries should note they default to a seven-day lookback and should extend that window as far back as October 2025 where telemetry retention permits. A match on the WinSparkle.dll path alone does not confirm infection, as NeedyMantis replaces a legitimate Poedit component; hash, file metadata, execution context, and network indicators should be correlated before drawing conclusions. The published C2 domain provides a useful indicator across DNS, proxy, and egress telemetry, while the firefox/21.0 user agent provides an additional hunting opportunity where HTTP-aware telemetry or TLS inspection is available. Even for organizations outside the current target profile, the DLL sideloading techniques used here are broadly applicable and worth building detection coverage for.
MITRE ATT&CK Techniques ▼
T1195.002 - Supply Chain Compromise: Compromise Software Supply Chain T1574.002 - Hijack Execution Flow: Dll Side-Loading T1036.005 - Masquerading: Match Legitimate Name Or Location T1027.007 - Obfuscated Files or Information: Dynamic Api Resolution T1027.013 - Obfuscated Files or Information: Encrypted/Encoded File T1622 - Debugger Evasion T1140 - Deobfuscate/Decode Files Or Information T1620 - Reflective Code Loading T1543.003 - Create or Modify System Process: Windows Service T1033 - System Owner/User Discovery T1057 - Process Discovery T1083 - File And Directory Discovery T1570 - Lateral Tool Transfer T1071.001 - Application Layer Protocol: Web Protocols T1573.001 - Encrypted Channel: Symmetric Cryptography T1132.001 - Data Encoding: Standard Encoding T1132.002 - Data Encoding: Non-Standard Encoding T1001.003 - Data Obfuscation: Protocol Impersonation
Target Industry ▼
Telecommunications Education
Source Country ▼
China
Source Region ▼
Asia
Story #2  |  September 28, 2026  |  AMERICAS

Email Policy Blind Spot Fuels Surge in SVG-Based Phishing and Malware Delivery

▶ expand
Scalable Vector Graphics (SVG) files are increasingly abused in phishing and malware campaigns, exploiting a classification gap: email policy may treat .svg as a harmless image while browsers parse and execute it as code. The extension is absent from default blocked-attachment lists on major platforms; because any malicious destination is embedded within the SVG or reached only once the browser opens it, the email body need carry no URL for pre-delivery gateway inspection. Attackers use this to render fake login pages, reconstruct malware archives in browser memory, or redirect victims to attacker-controlled infrastructure. Some campaigns produce byte-wise unique samples; others carry only a plaintext redirect line, leaving few static features for classifiers to evaluate. SVG ranked third in one industry dataset, behind PDF and HTML, with the same dataset measuring a roughly fiftyfold increase in malicious SVG attachments from 2024 to 2025; a three-day campaign in February 2026 delivered 1.2 million messages to over 53,000 organizations across 23 countries. Global credential phishing using HR, invoice, and voicemail lures accounts for the majority of volume, while a smaller cluster targets Colombia with remote access trojans (RATs) including AsyncRAT, Remcos, and DCRat, through judicial and tax-authority lures.
Analyst Comment
SVG may be absent from default blocked-attachment lists on major email platforms unless administrators apply additional restrictions, meaning many organizations may be permitting it without a deliberate policy decision. Reviewing whether your gateway applies any control to .svg is the immediate action, and for most environments where SVG has no routine business purpose, blocking or quarantining at delivery is a low-risk, high-value change. The mid-year decline before the August resurgence is consistent with format rotation rather than any reduction in capability, suggesting operators cycle between attachment types as detection rules catch up. In observed commodity campaigns, the first-stage architecture of a credential phishing chain and a RAT delivery chain via SVG are structurally identical, making the attachment an early interception point before objectives diverge later in the chain. For the plaintext redirect variant, where the file itself carries little to flag, web filtering covering destinations contacted after execution becomes especially important. The lures are workplace-generic and trigger when the attachment is opened, making delivery-layer controls the earliest defensive opportunity, supported by content inspection, web filtering, and endpoint protection rather than user recognition alone.
Story #3  |  October 2, 2026  |  EUROPE

Longlegs Sustains Warlock Ransomware Campaign Against Critical Infrastructure via SharePoint Exploitation and Kernel-Level Defense Evasion

▶ expand
Infrastructure / Water � Telecommunications � Government / Government Regional � Education
The China-nexus threat actor tracked as Longlegs, whose history predates the emergence of Warlock ransomware in June 2025, targeted at least four organizations over two months across Portuguese and Spanish-speaking countries in Europe, Africa, and Latin America, including a water utility, a telecommunications provider, a regional government body, and a university. The group continues to exploit on-premises SharePoint vulnerabilities; researchers assess the ToolShell-related flaws (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771) likely remain in its arsenal, using web shells to harvest ASP.NET machine keys and forge signed payloads for remote code execution within the SharePoint application pool. In an intrusion beginning July 22, attackers retrieved payloads from legitimate cloud services, used DLL sideloading to load malicious code, installed Visual Studio Code Insiders as a service for remote tunneling through Microsoft infrastructure, and used NetExec for Active Directory enumeration, credential spraying, and remote command execution. An endpoint detection and response (EDR) killer was deployed via the bring your own vulnerable driver (BYOVD) technique, reaching at least 40 hosts in about two hours; the driver identity was unconfirmed in this intrusion, though Longlegs used K7RKScan (CVE-2025-1055) in other recent attacks. Warlock was staged in the SYSVOL share and executed on at least 33 hosts.
Analyst Comment
The nine days between first observed malicious activity and ransomware deployment represent a meaningful detection and response window. Longlegs combined custom malicious components, including web shells and DLL sideloading payloads, with dual-use tooling and native Windows commands, making behavioral detection particularly important. VS Code tunnel activity from non-developer hosts and anomalous additions of domain accounts to local Administrators groups offer detection opportunities before the destructive phase. Executable files in SYSVOL are a high-priority late-stage signal; in this intrusion it served as the ransomware distribution mechanism. On-premises SharePoint Server deployments should be patched against the ToolShell-related CVEs and subsequent advisories; Microsoft additionally directs customers to rotate SharePoint ASP.NET machine keys and restart IIS. SharePoint Online in Microsoft 365 is not affected by these vulnerabilities. The recent focus on Portuguese and Spanish-speaking countries remains analytically unresolved; researchers assess it could reflect opportunistic targeting of exposed SharePoint servers or deliberate tasking, and geography alone should not be treated as a meaningful risk-reduction factor. The targeting of critical infrastructure by a China-nexus actor warrants continued monitoring, although current evidence does not establish espionage or disruptive objectives beyond the observed ransomware activity.
MITRE ATT&CK Techniques ▼
T1190 - Exploit Public-Facing Application T1059.001 - Command and Scripting Interpreter: Powershell T1059.003 - Command and Scripting Interpreter: Windows Command Shell T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1098.007 - Account Manipulation: Additional Local or Domain Groups T1068 - Exploitation For Privilege Escalation T1218.007 - Signed Binary Proxy Execution: Msiexec T1574.002 - Hijack Execution Flow: Dll Side-Loading T1562.001 - Impair Defenses: Disable Or Modify Tools T1036 - Masquerading T1070.004 - Indicator Removal on Host: File Deletion T1027.010 - Obfuscated Files or Information: Command Obfuscation T1110.003 - Brute Force: Password Spraying T1087.002 - Account Discovery: Domain Account T1482 - Domain Trust Discovery T1033 - System Owner/User Discovery T1018 - Remote System Discovery T1570 - Lateral Tool Transfer T1080 - Taint Shared Content T1219.001 - Remote Access Tools: IDE Tunneling T1105 - Ingress Tool Transfer T1486 - Data Encrypted For Impact
Target Industry ▼
Infrastructure / water Telecommunications Government / government regional Education
Target Region ▼
Europe
Target Country ▼
Europe
Source Country ▼
China
Source Region ▼
Asia
Story #4  |  September 29, 2026  |  AMERICAS

Active Exploitation of Citrix NetScaler Zero-Days Deploys WHIPSHOT and SLAPSHOT

▶ expand
Government � Financial Services � Technology � Education � Commercial
Active exploitation of two zero-day vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and Gateway appliances has been ongoing since at least early September 2026, likely affecting government, financial services, technology, education, and legal and professional services organizations in North America and Europe. CVE-2026-88772 (CVSS v4.0: 9.5) exploits a pre-authentication flaw in Datagram Transport Layer Security (DTLS) processing; telemetry analysis indicates malformed record headers corrupt packet engine memory and execute arbitrary code with root privileges. CVE-2026-88771 (CVSS v4.0: 9.5), an improper input validation flaw confirmed by Citrix as actively exploited, allows unauthenticated command execution on all deployments with no feature prerequisites. Post-exploitation, attackers modify Apache's configuration to host PHP web shells under non-PHP file extensions, establish persistent root access, and deploy two previously undocumented tools. WHIPSHOT, a PHP web shell, extracts Base64-encoded commands from native HTTP headers and returns spoofed HTTP 404 responses, masking activity in web access logs. SLAPSHOT, a Python TCP tunneler, proxies traffic to internal hosts, closes idle sessions after 15 minutes, self-terminates after 10 minutes of inactivity, and deletes its artifacts. In at least one confirmed intrusion, SLAPSHOT supported internal reconnaissance and credential theft. Citrix has issued patches for both vulnerabilities.
Analyst Comment
NetScaler ADC and Gateway appliances sit at the authentication perimeter, processing VPN sessions, LDAP and RADIUS credentials, and application access. Credential rotation guidance here is substantive, not precautionary. The GTIG report places exploitation of CVE-2026-88772 from at least early September 2026, with patches issued September 27, a zero-day window of at least three to four weeks on a device category that typically sits outside endpoint detection coverage. Patching is not remediation. WHIPSHOT and SLAPSHOT persist through patching because they live in the file system and configuration, not the vulnerability, and any appliance exposed during that window should be treated as potentially implanted until indicators have been actively checked. The hunting guidance in this report is operationally specific, but a negative result is not conclusive: SLAPSHOT removes its own artifacts after 10 minutes and WHIPSHOT returns 404 responses designed to blend into normal access logs. The toolkit reflects deliberate familiarity with this environment and counter-forensic awareness. Sector targeting is consistent with access-motivated objectives. Attribution remains unestablished in the primary reporting, though we assess with moderate confidence the operational maturity observed is inconsistent with commodity threat actors. CVE-2026-88771 requires no configuration prerequisite; DTLS mitigations specific to CVE-2026-88772 offer no protection against it.
Story #5  |  September 25, 2026

JADEPUFFER Uses Compromised Azure Service Principals for Destructive Cloud Operations

▶ expand
JADEPUFFER (tracked by Microsoft as Storm-3168), the threat actor behind the first documented agentic ransomware operation, compromised two Azure service principal machine identities in the same organization in early June 2026 and used them across an 18-hour operation combining reconnaissance, resource destruction, and credential collection. The first identity spent approximately 15 hours and 30 minutes enumerating Virtual Machines, subscriptions, and resource groups, completing more than 300 read operations. The second executed a seven-minute destructive sequence that deleted the majority of over 100 targeted Azure Storage accounts, an Azure Key Vault, a Function App, and an App Service plan. Attempted Azure SQL database deletions failed due to an unsupported API version; attempts to remove Azure Site Recovery and Azure Backup protection locks were also unsuccessful. About 30 minutes later, the same identity inventoried storage accounts before issuing more than 30 successful ListKeys requests for access keys. A possible initial access vector involves service principal credentials previously exposed in plaintext in a public GitHub issue, though Microsoft could not confirm this. No ransom note was observed and data exfiltration was not confirmed; Microsoft assessed the resource destruction, targeting of recovery mechanisms, and credential collection as consistent with ransomware or extortion preparation.
Analyst Comment
The seven-minute destructive phase is the most operationally significant detail here. By the time an alert fires and a human analyst begins investigating, the damage is likely already done, which shifts the primary defensive question toward pre-incident controls and resilience rather than real-time response, though detection remains essential for post-incident investigation and hunting. The root cause reflects a problem broader than a single credential exposure: service principals are routinely created at deployment speed, granted excess permissions, and left unreviewed, meaning that when one is compromised, defenders often have no behavioral baseline to identify anomalous activity. The partial failure of the attack is worth separating: SQL database deletions failed because the attacker used an outdated API version, which was an attacker error, not a defensive success; the backup and resource locks holding against a compromised identity with broad administrative permissions was a genuine control working as designed. One outcome is luck, the other is replicable. Both cloud infrastructure destruction and database extortion capabilities have now been attributed to the same actor, with the sequencing and relationship between them remaining unclear. The most durable question for defenders is whether workload identities in their environment have defined lifecycles, scoped permissions, behavioral baselines, and independent recovery protections that survive identity compromise.
Story #6  |  September 28, 2026

Infostealer Campaigns Target Corporate AI Accounts at Scale

▶ expand
Researchers analyzed more than one million infostealer records tied to AI services across 80,000-plus corporate domains, narrowing to 482 enterprises with exposed AI credentials, 68% of them billion-dollar organizations spanning 36 countries. Of the 482, 295 appeared in active stealer logs within the past 90 days, generating 5,434 records across 1,500 corporate email addresses. ChatGPT and OpenAI sessions appeared at 358 of the 482 companies, accounting for roughly 90% of all records; researchers attribute the skew to shadow adoption rather than any platform-specific weakness. Claude and Gemini appear infrequently because fewer employees have created corporate accounts on those platforms. Stolen AI logins carry compounded risk: session cookies represent a post-authentication state that attackers replay to skip the login process entirely, bypassing MFA; conversation history may contain source code, contracts, and customer data pasted into prompts; and stolen API keys allow attackers to run AI workloads at the victim's expense or resell access, a practice known as LLMjacking. Commodity infostealers including Vidar, LummaC2, StealC, and RedLine hijacked AI sessions in late August 2026 to drain paid usage; underground forums sold session cookies and API keys across the same period, some with money-back guarantees. Technology firms account for 144 of the 482 companies and 40% of all records; agent and automation platform exposure, where stolen sessions carry standing authorization into connected email, storage, and CRM systems, concentrates in healthcare, financial services, and technology.
Analyst Comment
The dataset's narrowing from over one million records to 482 verified enterprises strengthens rather than weakens confidence in the findings; these are confirmed corporate exposures, not infostealer noise. The exposure follows adoption, not platform choice; ChatGPT's dominance reflects its head start in corporate environments, and the August 2026 incident confirmed that other platforms face the same targeting pressure once their user base reaches sufficient scale. Defenders should not read the underrepresentation of other AI platforms as safety. In this analyst's assessment, the automation platform risk is likely underweighted in most current threat models: a stolen AI session exposes conversation history, but a stolen automation platform session carries standing authorization into email, CRM, and file storage, generating traffic from trusted vendor infrastructure that perimeter controls are unlikely to flag, representing lateral movement without intrusion, concentrated in healthcare, financial services, and technology. The practical starting point for most organizations is discovery; governance and technical controls cannot reach accounts IT does not know exist. Anthropic's August response provides a credible operational template: session invalidation, payment method removal, and proactive notification that the endpoint itself is compromised, not only the account. Organizations waiting for a stealer log to surface their exposure before acting on visibility are already behind the threat.

FEATURED RESOURCES

October 6, 2026
Anomali Cyber Watch

Anomali Cyber Watch: NeedyMantis, Warlock, Cloud Risks and more

Stay ahead of evolving cyber threats. Explore the latest on NeedyMantis malware, Warlock ransomware SharePoint exploitation, and corporate AI infostealers.
Read More
September 29, 2026
Anomali Cyber Watch

Anomali Cyber Watch: Windows, Salesforce & Citrix Threats

Latest cyber threats: Windows Defender & CLOSEDQUORUM implants, Salesforce SalesBleed data leaks, Oracle WAF bypasses, Citrix zero-days, and more.
Read More
September 28, 2026
AI
Operationalized Threat Intelligence

From Feeds to Agents: What the AI Shift Asks of Your Data Foundation

New Gartner® research examines AI in cyberthreat intelligence operations. Our view on why the data foundation decides what your agents can safely do.
Read More
Explore All