Download Privacy Needle App

Type to search

Cybersecurity

Microsoft Identifies NeedyMantis Malware Used for Long-Term Network Access

Share

Microsoft Threat Intelligence has identified a new modular malware framework, dubbed “NeedyMantis,” used by a China-based threat actor to maintain long-term, stealthy access to compromised networks.

The malware has been deployed in targeted intrusions against telecommunications companies, universities, medical nonprofits, intergovernmental organisations, and government contractors. Microsoft has linked the activity to a threat actor tracked as Storm-3069, although the company has not officially attributed the group to a specific Chinese nation-state.

Stealth and Evasion Techniques

NeedyMantis is designed specifically for post-compromise activity, meaning an attacker must first gain initial access to a network before the malware can be deployed. Once active, it communicates with attacker-controlled infrastructure using HTTPS and WebSockets to gather system information and load additional modules as required.

To avoid detection, the framework employs DLL sideloading, which allows malicious code to hide behind trusted applications such as Vim, curl, Poedit, and TightVNC. The malware also uses custom encrypted file archives and variable encryption keys to make static analysis significantly more difficult for security defenders.

Discovery and Detection

Researchers discovered NeedyMantis while investigating indicators of compromise associated with the DAEMON Tools supply chain compromise, an incident previously reported by Kaspersky. Evidence indicates the malware has been in use since at least October 2025.

Because the framework is modular, security experts suggest that the full extent of its capabilities may not yet be known. Analysts recommend that organisations focus on detecting suspicious behaviours, such as unusual file copying, unexpected DLL loading, and irregular network activity, rather than searching only for known malware signatures.

Microsoft suggests that deploying endpoint detection and response (EDR) tools in block mode can help remediate malicious artifacts that are identified after an initial breach has occurred.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.