New NeedyMantis Malware Gives Hackers Long-Term Backdoor Access to Breached Networks
Microsoft has published a technical analysis of NeedyMantis, a malware family used to maintain long-term access to networks that attackers have already broken into. It has appeared in a small number of targeted intrusions affecting telecommunications firms, universities, medical nonprofits, intergovernmental organisations, and government contractors, with activity dating back to at least October 2025.
Microsoft discovered the malware while investigating a supply chain attack on the DAEMON Tools Lite software, where signed installers were tampered with between April and May 2026. While one attack group, tracked as Storm-3069, was linked to that incident, Microsoft has not seen NeedyMantis itself distributed through a supply chain compromise. Instead, in observed cases, the malware arrives as a bundle containing a legitimate program, a malicious file disguised as one it normally loads, and an encrypted archive, a technique known as DLL sideloading. Legitimate tools misused this way include Poedit, curl, Vim, and TightVNC, as well as disguised files mimicking Microsoft Office, Broadcom, Intel, and NVIDIA components.
Once active, the malware unpacks further stages and establishes contact with a remote command server, later switching to a persistent connection that lets attackers load additional modules. Microsoft has not yet confirmed what those additional modules do, but has published file hashes, domains, and detection queries to help organisations check for signs of compromise.