Microsoft Warns NeedyMantis Malware Enables Persistent Network Access
Dubbed NeedyMantis, the malware operation has been active since at least October 2025.

Dubbed NeedyMantis, the malware operation has been active since at least October 2025.
Microsoft Threat Intelligence said in analysis, published on September 28 , that the malware has been used in hacking campaigns which have targeted telecommunications providers, universities and government-linked organizations.
Microsoft attributed NeedyMantis activity as emerging from China, although the company has not gone so far as to attribute the activity to the threat actor working on behalf of the Chinese state .
While it remains unknown how the NeedyMantis attackers gain initial access, what is known, as detailed by Microsoft Threat Intelligence, is NeedyMantis is composed of multiple components written in C++ and x64 shellcode These two elements have been discovered packaged alongside legitimate software, which installs the malware through DLL side-loading as part of a first-stage loader.
Microsoft noted that while Storm-3069, which has been associated with the with the Daemon Tools supply chain compromise , no evidence has been found of the malware being distributed in this way.
Microsoft found NeedyMantis while following up on indicators from Kaspersky's investigation into the supply chain attack on DAEMON Tools .
According to Microsoft, NeedyMantis is deployed onto the already compromised system directly by the attacker, who uses their remote hands-on access to install the required components on the machine.
Following this, a second-stage loader is deployed to further embed NeedyMantis into the compromised network, before the final stage sees NeedyMantis establish contact with a command and control server which provides the attacker with persistent access to the machine, as well as the ability to exfiltrate data or install additional components.
It could also not determine if all activity could be attributed to the same operator but at least one is Storm-3069.
Microsoft’s analysis of NeedyMantis suggested that it is only deployed after the threat actor has previously gained access to the compromised environment, therefore the malware is likely used to maintain long-term access and support follow-on operations.
The malware also contains anti-analysis techniques to hinder detection and analysis by security software and cyber defenders.
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis.
The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors.
However, the company also noted, To defend networks against the potential threat of cyber-attacks based around NeedyMantis, Microsoft has recommended the following mitigations:
What happened
Dubbed NeedyMantis, the malware operation has been active since at least October 2025.
Microsoft Threat Intelligence said in analysis, published on September 28 , that the malware has been used in hacking campaigns which have targeted telecommunications providers, universities and government-linked organizations.
Microsoft attributed NeedyMantis activity as emerging from China, although the company has not gone so far as to attribute the activity to the threat actor working on behalf of the Chinese state .
What changed
While it remains unknown how the NeedyMantis attackers gain initial access, what is known, as detailed by Microsoft Threat Intelligence, is NeedyMantis is composed of multiple components written in C++ and x64 shellcode These two elements have been discovered packaged alongside legitimate software, which installs the malware through DLL side-loading as part of a first-stage loader.
Microsoft noted that while Storm-3069, which has been associated with the with the Daemon Tools supply chain compromise , no evidence has been found of the malware being distributed in this way.
Microsoft found NeedyMantis while following up on indicators from Kaspersky's investigation into the supply chain attack on DAEMON Tools .
Who is affected
According to Microsoft, NeedyMantis is deployed onto the already compromised system directly by the attacker, who uses their remote hands-on access to install the required components on the machine.
Following this, a second-stage loader is deployed to further embed NeedyMantis into the compromised network, before the final stage sees NeedyMantis establish contact with a command and control server which provides the attacker with persistent access to the machine, as well as the ability to exfiltrate data or install additional components.
Why it matters
It could also not determine if all activity could be attributed to the same operator but at least one is Storm-3069.
Microsoft’s analysis of NeedyMantis suggested that it is only deployed after the threat actor has previously gained access to the compromised environment, therefore the malware is likely used to maintain long-term access and support follow-on operations.
Technical details
The malware also contains anti-analysis techniques to hinder detection and analysis by security software and cyber defenders.
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis.
The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors.
Response
However, the company also noted, To defend networks against the potential threat of cyber-attacks based around NeedyMantis, Microsoft has recommended the following mitigations:
Defenders can check their networks using the file hashes, domains, file paths, and hunting queries that Microsoft published and listed below.
What security teams should do
In the sample Microsoft analyzed in detail, the malicious file replaced WinSparkle.dll, the update component that Poedit uses.
Microsoft recommends several Defender settings: cloud-delivered protection, block at first sight, EDR in block mode, network protection, automatic attack disruption, and two attack surface reduction rules.
What remains unknown
While it remains unknown how the NeedyMantis attackers gain initial access, what is known, as detailed by Microsoft Threat Intelligence, is NeedyMantis is composed of multiple components written in C++ and x64 shellcode These two elements have been discovered packaged alongside legitimate software, which installs the malware through DLL side-loading as part of a first-stage loader.
It is unclear whether UNC6863 and Storm-3069 belong to the same group.
Microsoft has not said whether NeedyMantis is still in use, and the files it dated were first seen in October 2025 and May 2026.
Attribution
Infosecurity Magazine: Dubbed NeedyMantis, the malware operation has been active since at least October 2025.
The Hacker News: Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis.
What to watch next
Watch for additional victim details, indicators of compromise and follow-on exploitation reports.
Watch for revised vendor guidance, fixed versions and mitigation updates.