Skip to content
Tech News
← Back to articles

Microsoft Details 'NeedyMantis' Malware Used for Post-Compromise Network Access

read original more articles
GoKawiil Brief

Microsoft Threat Intelligence disclosed a previously unknown modular backdoor called NeedyMantis, active since at least October 2025, used in targeted intrusions against telecoms, universities, medical nonprofits, intergovernmental bodies and government contractors. The malware was found while investigating the DAEMON Tools supply chain compromise reported by Kaspersky in May, and Microsoft has linked some activity to a China-based actor it tracks as Storm-3069, though not all deployments are attributed to that group.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

Because NeedyMantis operates only after attackers already have network access, it highlights a defensive gap where security teams focus heavily on preventing initial breaches but may under-invest in detecting persistence and lateral activity afterward, according to Microsoft. Its modular, encrypted, custom-format design suggests the operators prioritized evading analysis tools and extending capabilities over time, which could make detection and attribution more difficult for defenders going forward.

Key Takeaways

Source: darkreading.com — Elizabeth Montalbano, 2026-09-29

Published there as: “'NeedyMantis' Provides Long-Term Access to Compromised Networks”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.