INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
NeedyMantis Provides Long-Term Access to Compromised Microsoft Networks
| 2026-09-28 15:56 CRITICAL HIGH CYBERATTACK (GENERAL)
Executive Summary
AI-generated
A previously unidentified malware family, dubbed "NeedyMantis," has been linked to a threat actor tracked as Storm-3069 based in China. The malware provides long-term stealth access to targeted networks once they've already infiltrated a system, revealing a potential blind spot for defenders. NeedyMantis is used by attackers in targeted intrusions against telecommunications companies, universities, medical nonprofits, intergovernmental organizations, and government contractors, with at least 5 affected entities identified. The malware communicates with attacker-controlled infrastructure over HTTPS and WebSockets, gathers information about the compromised system, and can load additional components as needed through a two-stage loader. Microsoft discovered NeedyMantis while investigating indicators of compromise associated with the DAEMON Tools supply chain compromise in May 2026; it has been used since at least October 2025.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
c82520••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
9cb68f••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
e842dd••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
co•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Salt TyphoonSalt Typhoon
Target & Sectors
GCC
GCC
NORTH_AMERICA
NORTH_AMERICA
educationeducation
telecommunicationstelecommunications
Incident Timeline
2025/09/29
Salt Typhoon, a China-backed threat group, breached the networks of telco providers in 2025.
Click on any entity below to view its context and source!
source_region
China
Related:
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Indeed, last year the China-backed threat group Salt Typhoon breached the networks of
telco providers
in a global spree
, demonstrating that
critical infrastructure
providers continue to be high-value targets for nation-state actors.
infrastructure
Microsoft 365
Related:
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Indeed, last year the China-backed threat group Salt Typhoon breached the networks of
telco providers
in a global spree
, demonstrating that
critical infrastructure
providers continue to be high-value targets for nation-state actors.
organisation
Reach Microsoft 365
Related:
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Indeed, last year the China-backed threat group Salt Typhoon breached the networks of
telco providers
in a global spree
, demonstrating that
critical infrastructure
providers continue to be high-value targets for nation-state actors.
organisation
Corporate Data
Indeed
Related:
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Indeed, last year the China-backed threat group Salt Typhoon breached the networks of
telco providers
in a global spree
, demonstrating that
critical infrastructure
providers continue to be high-value targets for nation-state actors.
threat_actor
Salt Typhoon
Related:
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Indeed, last year the China-backed threat group Salt Typhoon breached the networks of
telco providers
in a global spree
, demonstrating that
critical infrastructure
providers continue to be high-value targets for nation-state actors.
general_metric
365 Microsoft
Related:
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Indeed, last year the China-backed threat group Salt Typhoon breached the networks of
telco providers
in a global spree
, demonstrating that
critical infrastructure
providers continue to be high-value targets for nation-state actors.
at least October 2025
Threat actors used malware since at least October 2025 to maintain long-term access inside compromised networks.
Click on any entity below to view its context and source!
tactic
T1588.001 - Malware
Activity dates to at least October 2025, suggesting operators have quietly used the […] The post Microsoft Finds New Malware Used by Hackers to Maintain Secret Access Inside Target Networks appeared first on Cyber Security News .
organisation
Cyber Security News
Activity dates to at least October 2025, suggesting operators have quietly used the […] The post Microsoft Finds New Malware Used by Hackers to Maintain Secret Access Inside Target Networks appeared first on Cyber Security News .
2026/09/28
Threat actors used the NeedyMantis malware in targeted intrusions against various organizations.
Click on any entity below to view its context and source!
attribution
Microsoft Threat Intelligence
The malware, dubbed "NeedyMantis," is a modular framework that has been used in a limited number of targeted intrusions against
telecommunications companies
, universities, medical nonprofits, intergovernmental organizations, and government contractors, Microsoft Threat Intelligence revealed in
a blog post
yesterday.
industry
Telecommunications
The malware, dubbed "NeedyMantis," is a modular framework that has been used in a limited number of targeted intrusions against
telecommunications companies
, universities, medical nonprofits, intergovernmental organizations, and government contractors, Microsoft Threat Intelligence revealed in
a blog post
yesterday.
industry
Government
The malware, dubbed "NeedyMantis," is a modular framework that has been used in a limited number of targeted intrusions against
telecommunications companies
, universities, medical nonprofits, intergovernmental organizations, and government contractors, Microsoft Threat Intelligence revealed in
a blog post
yesterday.
attribution
NeedyMantis
The malware, dubbed "NeedyMantis," is a modular framework that has been used in a limited number of targeted intrusions against
telecommunications companies
, universities, medical nonprofits, intergovernmental organizations, and government contractors, Microsoft Threat Intelligence revealed in
a blog post
yesterday.
2026/09/28
Threat actors tracked as Storm-3069 used NeedyMantis, a modular post-compromise malware framework, to maintain long-term access and support follow-on operations in targeted intrusions involving telecommunications providers, universities, medical nonprofits, intergovernmental bodies, and government contractors.
Click on any entity below to view its context and source!
organisation
NeedyMantis
Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components to maintain long-term access and support follow-on operations.
Microsoft Threat Intelligence has uncovered NeedyMantis, a modular post-compromise malware framework designed to preserve covert access inside already-breached networks.
NeedyMantis is a modular post-compromise malware family deployed in limited targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors.
Microsoft discovered NeedyMantis while investigating indicators of compromise (IoCs) associated with the DAEMON Tools
supply chain compromise
, which
was reported
by Kaspersky in May.
organisation
Kaspersky
Microsoft discovered NeedyMantis while investigating indicators of compromise (IoCs) associated with the DAEMON Tools
supply chain compromise
, which
was reported
by Kaspersky in May.
organisation
Microsoft Security Blog
The post NeedyMantis: Unpacking a post-compromise malware family used in targeted operations appeared first on Microsoft Security Blog .
organisation
Microsoft Finds New
Microsoft Finds New Malware Used by Hackers to Maintain Secret Access Inside Target Networks.
organisation
Maintain Secret Access Inside Target Networks
Microsoft Finds New Malware Used by Hackers to Maintain Secret Access Inside Target Networks.
organisation
Storm-3069
Activity aligns with China-based threat actors, with Storm-3069 identified as one operator using NeedyMantis following the DAEMON Tools supply chain compromise.
The company linked the malware to a threat actor tracked as Storm-3069 that is based in China, though Microsoft did not link the actor to any Chinese nation-state groups.
organisation
Microsoft
The company linked the malware to a threat actor tracked as Storm-3069 that is based in China, though Microsoft did not link the actor to any Chinese nation-state groups.
organisation
DLL
The malware employs DLL sideloading, WebSockets-based command-and-control communications, and RC4 encryption.
It uses DLL sideloading to hide behind trusted applications such as Poedit, curl, Vim, and TightVNC, with malicious DLLs posing as components from major software vendors, according to Microsoft.
organisation
WebSockets
The malware employs DLL sideloading, WebSockets-based command-and-control communications, and RC4 encryption.
It communicates with attacker-controlled infrastructure over HTTPS and WebSockets, gathers information about the compromised system, and can load additional components as needed.
organisation
HTTPS
It communicates with attacker-controlled infrastructure over HTTPS and WebSockets, gathers information about the compromised system, and can load additional components as needed.
organisation
Mass Disinformation
Related:
Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign
Range of NeedyMantis Capabilities
organisation
Impacket
Unknown
In one intrusion, attackers used
Impacket
to copy the legitimate software and malicious files before execution.
organisation
AttackIQ
And though Microsoft revealed some capabilities of the malware, given its
modular nature
, it's likely that there are many others that remain unknown, according to Andrew Costis, engineering manager of the adversary research team at AttackIQ.
organisation
Costis
To that end, a key detection opportunity for defenders when it comes to NeedyMantis may be the attacker’s behavior — including file copying, DLL loading, and unusual network activity — rather than merely detecting artifacts of the malware itself, Costis says.
organisation
EDR
"
Another potential way to defend against NeedyMantis would be to run an organization's endpoint detection and response (EDR) in block mode in case antivirus (AV) protection does not detect the threat.
organisation
AV
"
Another potential way to defend against NeedyMantis would be to run an organization's endpoint detection and response (EDR) in block mode in case antivirus (AV) protection does not detect the threat.
Tactical Metrics
Metrics
infrastructure
Microsoft 365
Affected Product
Click for context!
Related:
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Indeed, last year the China-backed threat group Salt Typhoon breached the networks of
telco providers
in a global spree
, demonstrating that
critical infrastructure
providers continue to be high-value targets for nation-state actors.
Intelligence Sources
Dark Reading
2026-09-29
AlienVault OTX
2026-09-28
AlienVault OTX
2026-09-28
AlienVault OTX
2026-09-28
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T11:47
Comprehensive Tactical Telemetry
Highly Correlated Entities
19x
organisation
Identified Entity
NeedyMantis
entity
4x
industry
Targeted Sector
Telecommunications
sector
4x
target region
Target Country
China
country
3x
timeline
Temporal Reference
at least October 2025
date
2x
attribution
Attributing Entity
Microsoft Threat Intelligence
authority
2x
tactic
Cyber Operation Type
Espionage
tactic
2x
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
Contextual Telemetry
Context Block
4 METRICS
source region
Origin Country
China
country
infrastructure
Affected Product
Microsoft 365
software
threat actor
APT Group
Salt Typhoon
actor
general metric
Microsoft
365
microsoft
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.