Microsoft Details 'NeedyMantis' Malware Used for Post-Compromise Network Access
Microsoft Threat Intelligence disclosed a previously unknown modular backdoor called NeedyMantis, active since at least October 2025, used in targeted intrusions against telecoms, universities, medical nonprofits, intergovernmental bodies and government contractors. The malware was found while investigating the DAEMON Tools supply chain compromise reported by Kaspersky in May, and Microsoft has linked some activity to a China-based actor it tracks as Storm-3069, though not all deployments are attributed to that group.
GoKawiil's interpretation of the reporting above, not reported fact.
Because NeedyMantis operates only after attackers already have network access, it highlights a defensive gap where security teams focus heavily on preventing initial breaches but may under-invest in detecting persistence and lateral activity afterward, according to Microsoft. Its modular, encrypted, custom-format design suggests the operators prioritized evading analysis tools and extending capabilities over time, which could make detection and attribution more difficult for defenders going forward.
- NeedyMantis is a modular backdoor enabling long-term post-compromise access, not initial infiltration.
- Microsoft ties some activity to China-based actor Storm-3069, without confirming state sponsorship or attributing all uses.
- The malware surfaced during investigation of the DAEMON Tools supply chain compromise reported by Kaspersky in May.
Source: darkreading.com — Elizabeth Montalbano, 2026-09-29
Published there as: “'NeedyMantis' Provides Long-Term Access to Compromised Networks”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.