Microsoft Identifies NeedyMantis Malware Used for Long-Term Network Access
Share
Microsoft Threat Intelligence has identified a new modular malware framework, dubbed “NeedyMantis,” used by a China-based threat actor to maintain long-term, stealthy access to compromised networks.
The malware has been deployed in targeted intrusions against telecommunications companies, universities, medical nonprofits, intergovernmental organisations, and government contractors. Microsoft has linked the activity to a threat actor tracked as Storm-3069, although the company has not officially attributed the group to a specific Chinese nation-state.
Stealth and Evasion Techniques
NeedyMantis is designed specifically for post-compromise activity, meaning an attacker must first gain initial access to a network before the malware can be deployed. Once active, it communicates with attacker-controlled infrastructure using HTTPS and WebSockets to gather system information and load additional modules as required.
To avoid detection, the framework employs DLL sideloading, which allows malicious code to hide behind trusted applications such as Vim, curl, Poedit, and TightVNC. The malware also uses custom encrypted file archives and variable encryption keys to make static analysis significantly more difficult for security defenders.
Discovery and Detection
Researchers discovered NeedyMantis while investigating indicators of compromise associated with the DAEMON Tools supply chain compromise, an incident previously reported by Kaspersky. Evidence indicates the malware has been in use since at least October 2025.
Because the framework is modular, security experts suggest that the full extent of its capabilities may not yet be known. Analysts recommend that organisations focus on detecting suspicious behaviours, such as unusual file copying, unexpected DLL loading, and irregular network activity, rather than searching only for known malware signatures.
Microsoft suggests that deploying endpoint detection and response (EDR) tools in block mode can help remediate malicious artifacts that are identified after an initial breach has occurred.




Leave a Reply