‘NeedyMantis’ Provides Long-Term Access to Compromised Networks

A previously unknown malware framework, dubbed “NeedyMantis,” has been discovered by Microsoft Threat Intelligence providing attackers with long-term access to compromised networks. This sophisticated tool has been used in targeted intrusions against organizations such as telcos, universities, medical nonprofits, and government contractors. The discovery reveals a potential blind spot for defenders who focus primarily on initial intrusion rather than post-compromise activity.

NeedyMantis is a modular framework that allows attackers to gain stealthy access to networks once they have already infiltrated a system. It combines multiple loaders, custom encrypted file archives, and modular components that enable operators to evade analysis and extend functionality through additional modules. This malware has been used in a limited number of targeted intrusions since at least October 2025.

The discovery of NeedyMantis was made while investigating indicators of compromise (IoCs) associated with the DAEMON Tools supply chain compromise, which was reported by Kaspersky in May. Microsoft linked the malware to a threat actor tracked as Storm-3069 that is based in China, although they did not conclude that all deployments of the malware are tied to this group.

At its core, NeedyMantis is a modular backdoor designed for post-compromise activity, which means an attacker must have already gained initial access to a network to deploy the malware. It communicates with attacker-controlled infrastructure over HTTPS and WebSockets, gathers information about the compromised system, and can load additional components as needed.

One of the most concerning aspects of NeedyMantis is its ability to make malicious code look legitimate by hiding behind trusted applications such as Poedit, curl, Vim, and TightVNC. Malicious DLLs pose as components from major software vendors, making it difficult for defenders to detect the malware.

The range of capabilities offered by NeedyMantis remains largely unknown due to its modular nature. However, Microsoft has revealed some of its features, including its use of custom archives, changing encryption keys, and other techniques designed to make static analysis harder. The question now is what happens after entry: can additional modules be loaded, and if so, what capabilities do they offer?

Andrew Costis, engineering manager of the adversary research team at AttackIQ, suggests that NeedyMantis is likely being used for cyber-espionage activity given its target base. For organizations such as telcos or government contractors, he advises focusing on detecting post-compromise activity rather than just initial intrusion.

In light of this discovery, defenders should be aware of the need to monitor network activity more closely and detect unusual behavior that may indicate a long-term compromise. Microsoft’s revelation highlights the importance of ongoing monitoring and analysis in detecting sophisticated threats like NeedyMantis. By being vigilant and proactive, organizations can reduce their risk of falling victim to such attacks and maintain the security of their networks.


Source: Dark Reading — 2026-09-29