www.darkreading.com 29 Sept 2026, 15:12 UTC

Microsoft Exposes NeedyMantis Malware in China Linked Intrusions

CyberSIXT Evidence Panel
Threat Actor
Storm-3069

MICROSOFT Threat Intelligence has disclosed a China-based threat actor using a previously unidentified modular malware framework codenamed NeedyMantis to sustain long-term, post-compromise access in targeted intrusions. The operations, active since at least October 2025, have affected telecommunications providers, universities, medical non-profits, intergovernmental organisations, and government contractors.

While Microsoft attributes some activity to Storm-3069, it stops short of linking all deployments to a single group, and notes that not every NeedyMantis instance may be connected to Storm-3069.

NeedyMantis is designed for post‑compromise activity and is spread via a two‑stage loader that employs DLL sideloading to masquerade as legitimate software, including Poedit, curl, Vim, and TightVNC. The framework uses custom encrypted file archives and a modular component architecture to load additional capabilities as needed, making static analysis harder.

In one observed intrusion, Impacket tools were used to copy legitimate software and malicious files before execution, illustrating a method by which the malware can be introduced after initial access. The loader and payloads have been reported as being packaged alongside legitimate programs, with the first stage masquerading as a required DLL.

Defence guidance centred on detection of attacker behaviour—such as file copying, DLL loading, and unusual network activity—rather than solely artefacts of the malware. Microsoft also suggests endpoint detection and response in block mode to remediate post‑breach activity that AV may miss, emphasising the need to interrupt hands‑on keyboard deployment and to validate adversarial exposure in practical tests. Further evidence and analysis are expected as researchers study this modular framework.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline