‘NeedyMantis’ Provides Long-Term Access to Compromised Networks

Cyberattacks can be devastating to organizations, but what happens after an initial breach is just as critical as the attack itself. A newly discovered malware framework, dubbed “NeedyMantis,” has been found providing long-term access to compromised networks, highlighting a potential blind spot for defenders.

Microsoft’s Threat Intelligence team has identified NeedyMantis as a modular backdoor used in targeted intrusions against various organizations, including telecommunications companies, universities, medical nonprofits, intergovernmental organizations, and government contractors. The malware is linked to a China-based threat actor tracked as Storm-3069, although Microsoft notes that not all deployments of the malware are tied to this group.

NeedyMantis works by communicating with attacker-controlled infrastructure over HTTPS and WebSockets, gathering information about the compromised system, and loading additional components as needed. It’s designed for post-compromise activity, meaning an attacker must already have gained initial access to a network to deploy the malware. The malware can make malicious code look legitimate by hiding behind trusted applications, such as Poedit, curl, Vim, and TightVNC.

What sets NeedyMantis apart is its ability to evade analysis and extend functionality through additional modules. Its modular nature means that there are likely many unknown capabilities, according to Andrew Costis, engineering manager of the adversary research team at AttackIQ. “The question is what happens after entry,” he says. “Its main component can load further modules, although their capabilities remain unconfirmed.”

The use of NeedyMantis raises concerns about cyber-espionage activity, particularly given its target base. Microsoft discovered the malware while investigating indicators of compromise (IoCs) associated with the DAEMON Tools supply chain compromise, which was reported by Kaspersky in May.

While Microsoft has not given a clear motive for Storm-3069’s use of NeedyMantis, it’s likely that attackers are interested in accessing sensitive systems and maintaining access over an extended period. For organizations affected by NeedyMantis, this means that detection based on behavior is crucial. Analysts must look for signs of post-compromise activity, such as unusual network traffic or suspicious application behavior.

Ultimately, the discovery of NeedyMantis highlights the importance of ongoing monitoring and analysis in the face of a breach. Organizations must be prepared to detect and respond to post-compromise activity, rather than just focusing on initial intrusion prevention. By doing so, they can reduce the risk of long-term access being maintained by attackers, minimizing the damage caused by cyberattacks.


Source: Dark Reading — 2026-09-29