www.infosecurity-magazine.com 29 Sept 2026, 13:30 UTC

Microsoft Uncovers NeedyMantis Malware Enabling Stealthy Long-Term Access

CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
Storm-3069

MICROSOFT Threat Intelligence has disclosed a stealthy malware framework, dubbed NeedyMantis, used to maintain long-term, post-compromise access within organisations. Active since at least October 2025, the operation has targeted telecommunications providers, universities and government‑linked organisations. While attribution points to China‑linked activity, Microsoft cautions it has not concluded that all operations are conducted by the same actor, though one cluster has been associated with the Storm-3069 group.

NeedyMantis appears to be deployed after initial access is established, suggesting its role is to enable persistence and support follow‑on operations. The framework comprises multiple components written in C++ and x64 shellcode, delivered as part of a package that includes legitimate software and installs the malware via DLL side‑loading as a first‑stage loader.

Evidence indicates NeedyMantis is delivered by the attacker directly onto an already compromised system, using open‑source software downloads to disguise activity. Components are hidden alongside tools such as Poedit, curl, Vim and TightVNC, with some payloads masquerading as fake Microsoft Office, Broadcom, Intel and NVIDIA DLLs.

The malware features anti‑analysis techniques to hinder detection, followed by a second‑stage loader to deepen persistence and enable data exfiltration or further component installation, with a final stage establishing contact with a command and control server. Microsoft notes that supply chain compromise remains a theoretical concern but has not observed NeedyMantis distributed via known supply chain events like the Daemon Tools incident.

Defences emphasise cloud protection, Defender for Endpoint in block mode, network protection, EDR in block mode and automatic attack disruption to counter NeedyMantis activity.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline