DKDKCISSPSearch
Cyber Attacks

Microsoft Warns NeedyMantis Malware Enables Persistent Network Access

Dubbed NeedyMantis, the malware operation has been active since at least October 2025.

DKCISSP News DeskInfosecurity Magazine29 Sept 2026, 7:00 pm
Microsoft Warns NeedyMantis Malware Enables Persistent Network Access
Image courtesy of Infosecurity Magazine. Original report
DKCISSP REPORT

Dubbed NeedyMantis, the malware operation has been active since at least October 2025.

Microsoft Threat Intelligence said in analysis, published on September 28 , that the malware has been used in hacking campaigns which have targeted telecommunications providers, universities and government-linked organizations.

Microsoft attributed NeedyMantis activity as emerging from China, although the company has not gone so far as to attribute the activity to the threat actor working on behalf of the Chinese state .

While it remains unknown how the NeedyMantis attackers gain initial access, what is known, as detailed by Microsoft Threat Intelligence, is NeedyMantis is composed of multiple components written in C++ and x64 shellcode These two elements have been discovered packaged alongside legitimate software, which installs the malware through DLL side-loading as part of a first-stage loader.

Microsoft noted that while Storm-3069, which has been associated with the with the Daemon Tools supply chain compromise , no evidence has been found of the malware being distributed in this way.

Some of the open-source software abused by NeedyMantis during the delivery includes Poedit, curl, Vim and TightVNC.

According to Microsoft, NeedyMantis is deployed onto the already compromised system directly by the attacker, who uses their remote hands-on access to install the required components on the machine.

Following this, a second-stage loader is deployed to further embed NeedyMantis into the compromised network, before the final stage sees NeedyMantis establish contact with a command and control server which provides the attacker with persistent access to the machine, as well as the ability to exfiltrate data or install additional components.

It could also not determine if all activity could be attributed to the same operator but at least one is Storm-3069.

Microsoft’s analysis of NeedyMantis suggested that it is only deployed after the threat actor has previously gained access to the compromised environment, therefore the malware is likely used to maintain long-term access and support follow-on operations.

The malware also contains anti-analysis techniques to hinder detection and analysis by security software and cyber defenders.

Microsoft has also seen elements used as part of NeedyMantis attacks posing as fake Microsoft Office, Broadcom, Intel and NVIDIA DLL components.

By packaging this activity alongside downloads of open-source software, the attackers are attempting to disguise their malicious activity.

However, the company also noted, To defend networks against the potential threat of cyber-attacks based around NeedyMantis, Microsoft has recommended the following mitigations:

What happened

Dubbed NeedyMantis, the malware operation has been active since at least October 2025.

Microsoft Threat Intelligence said in analysis, published on September 28 , that the malware has been used in hacking campaigns which have targeted telecommunications providers, universities and government-linked organizations.

Microsoft attributed NeedyMantis activity as emerging from China, although the company has not gone so far as to attribute the activity to the threat actor working on behalf of the Chinese state .

What changed

While it remains unknown how the NeedyMantis attackers gain initial access, what is known, as detailed by Microsoft Threat Intelligence, is NeedyMantis is composed of multiple components written in C++ and x64 shellcode These two elements have been discovered packaged alongside legitimate software, which installs the malware through DLL side-loading as part of a first-stage loader.

Microsoft noted that while Storm-3069, which has been associated with the with the Daemon Tools supply chain compromise , no evidence has been found of the malware being distributed in this way.

Some of the open-source software abused by NeedyMantis during the delivery includes Poedit, curl, Vim and TightVNC.

Who is affected

According to Microsoft, NeedyMantis is deployed onto the already compromised system directly by the attacker, who uses their remote hands-on access to install the required components on the machine.

Following this, a second-stage loader is deployed to further embed NeedyMantis into the compromised network, before the final stage sees NeedyMantis establish contact with a command and control server which provides the attacker with persistent access to the machine, as well as the ability to exfiltrate data or install additional components.

Why it matters

It could also not determine if all activity could be attributed to the same operator but at least one is Storm-3069.

Microsoft’s analysis of NeedyMantis suggested that it is only deployed after the threat actor has previously gained access to the compromised environment, therefore the malware is likely used to maintain long-term access and support follow-on operations.

Technical details

The malware also contains anti-analysis techniques to hinder detection and analysis by security software and cyber defenders.

Microsoft has also seen elements used as part of NeedyMantis attacks posing as fake Microsoft Office, Broadcom, Intel and NVIDIA DLL components.

By packaging this activity alongside downloads of open-source software, the attackers are attempting to disguise their malicious activity.

Response

However, the company also noted, To defend networks against the potential threat of cyber-attacks based around NeedyMantis, Microsoft has recommended the following mitigations:

What remains unknown

While it remains unknown how the NeedyMantis attackers gain initial access, what is known, as detailed by Microsoft Threat Intelligence, is NeedyMantis is composed of multiple components written in C++ and x64 shellcode These two elements have been discovered packaged alongside legitimate software, which installs the malware through DLL side-loading as part of a first-stage loader.

Attribution

Infosecurity Magazine: Dubbed NeedyMantis, the malware operation has been active since at least October 2025.

What to watch next

Watch for additional victim details, indicators of compromise and follow-on exploitation reports.

MORE IN CYBER ATTACKS

More cybersecurity reporting

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix LuresThe Hacker News · 30 Sept 2026, 9:22 pmRatHat's Evolving C2 Panel Points to Malware-as-a-Service Model - Infosecurity MagazineInfosecurity Magazine · 29 Sept 2026, 8:00 pmMicrosoft Warns NeedyMantis Malware Enables Persistent Network AccessInfosecurity Magazine · 29 Sept 2026, 7:00 pmBitget Says Suspected North Korean Hackers Stole $351.6M After Backend CompromiseThe Hacker News · 26 Sept 2026, 1:39 pm