Microsoft Flags NeedyMantis: Stealthy Malware Giving Attackers Long-Term Network Access
Microsoft Threat Intelligence has published research on a new malware framework called NeedyMantis, which has been used since at least October 2025 to keep attackers embedded inside compromised networks for long periods. The campaigns have targeted telecommunications providers, universities and government-linked organisations. Microsoft says the activity appears to originate from China, though it has not confirmed a link to a state-sponsored actor and has attributed at least one instance to a group tracked as Storm-3069.
According to Microsoft, NeedyMantis is only deployed after attackers already have a foothold in a network, meaning it is used to maintain access and support further malicious activity rather than to gain initial entry. It is unclear how attackers first break in, but the malware itself is built from multiple components written in C++ and x64 shellcode, and is installed manually by attackers using hands-on remote access.
To avoid detection, NeedyMantis is packaged alongside legitimate open-source tools such as Poedit, curl, Vim and TightVNC, using a technique called DLL side-loading. Some components are disguised as fake Microsoft Office, Broadcom, Intel or NVIDIA files. The malware also includes anti-analysis features designed to make it harder for security teams and software to detect and investigate.