Infosecurity Magazine iconInfosecurity MagazineSep 29, 2026 ~5 min source read

Microsoft: NeedyMantis Malware Used to Maintain Persistent Access in Breached Networks

Microsoft Threat Intelligence describes NeedyMantis as a multi-component, post-compromise malware framework observed since October 2025 that enables long-term network access and data exfiltration. The activity has been linked to operators from China, including one tracked as Storm-3069.

Share this story

Send the public story page.

Useful takeaways from this story.

NeedyMantis is deployed after attackers gain initial access and is designed to maintain prolonged, stealthy presence within networks.

Attackers deliver the malware via DLL side-loading bundled with legitimate open-source installers (Poedit, curl, Vim, TightVNC) and fake vendor DLLs.

Microsoft links at least one operator to Storm-3069 and highlights anti-analysis features, multi-stage loaders, and C2 channels for persistence and exfiltration.

# What Microsoft found

# How NeedyMantis is used NeedyMantis is a post-compromise toolset. Microsoft's analysis indicates attackers first gain access to an environment by other means, then install NeedyMantis to keep long-term access and enable follow-on operations. The framework contains multiple components written in C++ and x64 shellcode. The malware deploys anti-analysis techniques to evade detection and hinder defensive analysis.

Delivery and deployment are hands-on. Microsoft observed operators installing components directly on compromised systems and packaging malicious files alongside legitimate software downloads to disguise activity. The installation chain frequently uses DLL side-loading as the first-stage loader.

# Delivery techniques observed

  • Legitimate open-source software abused as cover: Poedit, curl, Vim and TightVNC were seen packaged with NeedyMantis artifacts.
  • Fake vendor DLLs used as decoys: components posing as Microsoft Office, Broadcom, Intel and NVIDIA DLLs have been observed.
  • Multi-stage loaders: the initial loader is followed by a second-stage loader to embed the framework, then a final stage establishes command-and-control (C2) connectivity for persistence and data exfiltration.

# Link to Storm-3069 and supply chain context Microsoft identified Storm-3069 as one operator associated with NeedyMantis activity. Storm-3069 has prior linkage to a supply chain compromise involving DAEMON Tools, but Microsoft did not find evidence that NeedyMantis itself was distributed via that supply chain compromise. Microsoft notes supply chain activity remains a possible means for actors to gain the necessary access to deploy the malware, but it did not confirm supply chain distribution of NeedyMantis.

# Operational impact and defender actions NeedyMantis provides attackers with persistent remote access, the ability to exfiltrate data, and to deploy additional components. The malware's anti-analysis features and use of legitimate software as a delivery vehicle increase the chance of prolonged compromise if not detected.

Microsoft published indicators and hunting queries defenders can use. The company also recommended configuration and product-level mitigations focused on rapid detection and blocking.

# Microsoft mitigation recommendations

  • Turn on cloud-delivered protection and enable block-at-first-sight to rapidly identify and block new and unknown malware variants.
  • Run Endpoint Detection and Response (EDR) in block mode so Microsoft Defender for Endpoint can block malicious artifacts.
  • Enable network protection in Microsoft Defender for Endpoint.
  • Configure automatic attack disruption in Microsoft Defender XDR to interrupt attacker activity.

These measures are presented as immediate controls defenders can enable within Microsoft security products to reduce the chance of successful deployment and persistence of NeedyMantis.

# Bottom line NeedyMantis is a stealthy, multi-component post-compromise framework that attackers use to remain hidden and maintain long-term access. Delivery via DLL side-loading bundled with legitimate software and use of anti-analysis techniques make detection harder. Organizations should use the published indicators and consider the listed product configurations to reduce exposure and disrupt active intrusions.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app