Security News

Microsoft Flags NeedyMantis: Stealthy Malware Giving Attackers Long-Term Network Access

Infosecurity Magazine · 29 Sept 2026
Key Takeaway Businesses should monitor for unusual DLL loading behaviour tied to trusted software and ensure endpoint security tools are updated to detect disguised, persistence-focused malware like NeedyMantis.

Microsoft Threat Intelligence has published research on a new malware framework called NeedyMantis, which has been used since at least October 2025 to keep attackers embedded inside compromised networks for long periods. The campaigns have targeted telecommunications providers, universities and government-linked organisations. Microsoft says the activity appears to originate from China, though it has not confirmed a link to a state-sponsored actor and has attributed at least one instance to a group tracked as Storm-3069.

According to Microsoft, NeedyMantis is only deployed after attackers already have a foothold in a network, meaning it is used to maintain access and support further malicious activity rather than to gain initial entry. It is unclear how attackers first break in, but the malware itself is built from multiple components written in C++ and x64 shellcode, and is installed manually by attackers using hands-on remote access.

To avoid detection, NeedyMantis is packaged alongside legitimate open-source tools such as Poedit, curl, Vim and TightVNC, using a technique called DLL side-loading. Some components are disguised as fake Microsoft Office, Broadcom, Intel or NVIDIA files. The malware also includes anti-analysis features designed to make it harder for security teams and software to detect and investigate.

malware China persistence DLL side-loading threat intelligence

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.