DKDKCISSPSearch
Cyber AttacksDEVELOPING

Microsoft Warns NeedyMantis Malware Enables Persistent Network Access

Dubbed NeedyMantis, the malware operation has been active since at least October 2025.

DKCISSP News DeskInfosecurity Magazine29 Sept 2026, 7:00 pm
Microsoft Warns NeedyMantis Malware Enables Persistent Network Access
Image courtesy of Infosecurity Magazine. Original report
DKCISSP REPORT

Dubbed NeedyMantis, the malware operation has been active since at least October 2025.

Microsoft Threat Intelligence said in analysis, published on September 28 , that the malware has been used in hacking campaigns which have targeted telecommunications providers, universities and government-linked organizations.

Microsoft attributed NeedyMantis activity as emerging from China, although the company has not gone so far as to attribute the activity to the threat actor working on behalf of the Chinese state .

While it remains unknown how the NeedyMantis attackers gain initial access, what is known, as detailed by Microsoft Threat Intelligence, is NeedyMantis is composed of multiple components written in C++ and x64 shellcode These two elements have been discovered packaged alongside legitimate software, which installs the malware through DLL side-loading as part of a first-stage loader.

Microsoft noted that while Storm-3069, which has been associated with the with the Daemon Tools supply chain compromise , no evidence has been found of the malware being distributed in this way.

Microsoft found NeedyMantis while following up on indicators from Kaspersky's investigation into the supply chain attack on DAEMON Tools .

According to Microsoft, NeedyMantis is deployed onto the already compromised system directly by the attacker, who uses their remote hands-on access to install the required components on the machine.

Following this, a second-stage loader is deployed to further embed NeedyMantis into the compromised network, before the final stage sees NeedyMantis establish contact with a command and control server which provides the attacker with persistent access to the machine, as well as the ability to exfiltrate data or install additional components.

It could also not determine if all activity could be attributed to the same operator but at least one is Storm-3069.

Microsoft’s analysis of NeedyMantis suggested that it is only deployed after the threat actor has previously gained access to the compromised environment, therefore the malware is likely used to maintain long-term access and support follow-on operations.

The malware also contains anti-analysis techniques to hinder detection and analysis by security software and cyber defenders.

Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis.

The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors.

However, the company also noted, To defend networks against the potential threat of cyber-attacks based around NeedyMantis, Microsoft has recommended the following mitigations:

What happened

Dubbed NeedyMantis, the malware operation has been active since at least October 2025.

Microsoft Threat Intelligence said in analysis, published on September 28 , that the malware has been used in hacking campaigns which have targeted telecommunications providers, universities and government-linked organizations.

Microsoft attributed NeedyMantis activity as emerging from China, although the company has not gone so far as to attribute the activity to the threat actor working on behalf of the Chinese state .

What changed

While it remains unknown how the NeedyMantis attackers gain initial access, what is known, as detailed by Microsoft Threat Intelligence, is NeedyMantis is composed of multiple components written in C++ and x64 shellcode These two elements have been discovered packaged alongside legitimate software, which installs the malware through DLL side-loading as part of a first-stage loader.

Microsoft noted that while Storm-3069, which has been associated with the with the Daemon Tools supply chain compromise , no evidence has been found of the malware being distributed in this way.

Microsoft found NeedyMantis while following up on indicators from Kaspersky's investigation into the supply chain attack on DAEMON Tools .

Who is affected

According to Microsoft, NeedyMantis is deployed onto the already compromised system directly by the attacker, who uses their remote hands-on access to install the required components on the machine.

Following this, a second-stage loader is deployed to further embed NeedyMantis into the compromised network, before the final stage sees NeedyMantis establish contact with a command and control server which provides the attacker with persistent access to the machine, as well as the ability to exfiltrate data or install additional components.

Why it matters

It could also not determine if all activity could be attributed to the same operator but at least one is Storm-3069.

Microsoft’s analysis of NeedyMantis suggested that it is only deployed after the threat actor has previously gained access to the compromised environment, therefore the malware is likely used to maintain long-term access and support follow-on operations.

Technical details

The malware also contains anti-analysis techniques to hinder detection and analysis by security software and cyber defenders.

Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis.

The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors.

Response

However, the company also noted, To defend networks against the potential threat of cyber-attacks based around NeedyMantis, Microsoft has recommended the following mitigations:

Defenders can check their networks using the file hashes, domains, file paths, and hunting queries that Microsoft published and listed below.

What security teams should do

In the sample Microsoft analyzed in detail, the malicious file replaced WinSparkle.dll, the update component that Poedit uses.

Microsoft recommends several Defender settings: cloud-delivered protection, block at first sight, EDR in block mode, network protection, automatic attack disruption, and two attack surface reduction rules.

What remains unknown

While it remains unknown how the NeedyMantis attackers gain initial access, what is known, as detailed by Microsoft Threat Intelligence, is NeedyMantis is composed of multiple components written in C++ and x64 shellcode These two elements have been discovered packaged alongside legitimate software, which installs the malware through DLL side-loading as part of a first-stage loader.

It is unclear whether UNC6863 and Storm-3069 belong to the same group.

Microsoft has not said whether NeedyMantis is still in use, and the files it dated were first seen in October 2025 and May 2026.

Attribution

Infosecurity Magazine: Dubbed NeedyMantis, the malware operation has been active since at least October 2025.

The Hacker News: Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis.

What to watch next

Watch for additional victim details, indicators of compromise and follow-on exploitation reports.

Watch for revised vendor guidance, fixed versions and mitigation updates.

MORE IN CYBER ATTACKS

More cybersecurity reporting

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix LuresThe Hacker News · 30 Sept 2026, 9:22 pmRatHat's Evolving C2 Panel Points to Malware-as-a-Service Model - Infosecurity MagazineInfosecurity Magazine · 29 Sept 2026, 8:00 pmBitget Says Suspected North Korean Hackers Stole $351.6M After Backend CompromiseThe Hacker News · 26 Sept 2026, 1:39 pmKiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber AttackThe Hacker News · 26 Sept 2026, 1:18 pm