
A previously unidentified malware family is giving attackers long-term stealth access to targeted networks once they've already infiltrated a system, revealing a potential blind spot for defenders that tend to focus more on initial intrusion rather than post-compromise activity.
The malware, dubbed "NeedyMantis," is a modular framework that has been used in a limited number of targeted intrusions against telecommunications companies, universities, medical nonprofits, intergovernmental organizations, and government contractors, Microsoft Threat Intelligence revealed in a blog post yesterday.
The company linked the malware to a threat actor tracked as Storm-3069 that is based in China, though Microsoft did not link the actor to any Chinese nation-state groups. However, Microsoft has not concluded that all deployments of the malware are tied to Storm-3069, the company said.
Microsoft discovered NeedyMantis while investigating indicators of compromise (IoCs) associated with the DAEMON Tools supply chain compromise, which was reported by Kaspersky in May. The malware, used since at least October 2025, combines multiple loaders, custom encrypted file archives, a custom executable file format, and modular components that enable operators to evade analysis and extend functionality through additional modules.
"These characteristics, combined with its use in targeted intrusions, make NeedyMantis a useful case study for understanding how threat actors establish and maintain long-term access within victim environments," according to Microsoft Threat Intelligence.
How NeedyMantis Works
At its core, NeedyMantis is a modular backdoor designed for post-compromise activity, which means an attacker already must have gained initial access to a network to deploy the malware. It communicates with attacker-controlled infrastructure over HTTPS and WebSockets, gathers information about the compromised system, and can load additional components as needed.
Distributed by a two-stage loader, NeedyMantis can make malicious code look legitimate. It uses DLL sideloading to hide behind trusted applications such as Poedit, curl, Vim, and TightVNC, with malicious DLLs posing as components from major software vendors, according to Microsoft.
"The loader and archive have been found packaged alongside legitimate software, with the first-stage loader — masquerading as a required DLL — being loaded through DLL sideloading," according to the post.
The malware also can peel back layers of encrypted and compressed payloads, with its loaders using custom archives, changing encryption keys, and employing other techniques designed to make static analysis harder.
Range of NeedyMantis Capabilities Unknown
In one intrusion, attackers used Impacket to copy the legitimate software and malicious files before execution. "This activity occurred after the actor had already obtained access to the environment and illustrates one method by which NeedyMantis can be introduced during an intrusion post-compromise," according to the post.
And though Microsoft revealed some capabilities of the malware, given its modular nature, it's likely that there are many others that remain unknown, according to Andrew Costis, engineering manager of the adversary research team at AttackIQ.
"The question is what happens after entry," he tells Dark Reading. "Its main component can load further modules, although their capabilities remain unconfirmed. Finding the first stage may not reveal everything an operator can do."
Detection Based on Behavior
Microsoft also did not give a clear motive for Storm-3069's use of NeedyMantis. However, given its target base, there is a high likelihood that attackers are interested in cyber-espionage activity, Costis surmises.
"For a telecom or government contractor, I'd worry about someone quietly moving toward sensitive systems and maintaining access long enough to gather intelligence," he says.
Indeed, last year the China-backed threat group Salt Typhoon breached the networks of telco providersin a global spree, demonstrating that critical infrastructure providers continue to be high-value targets for nation-state actors.
That makes detection of post-compromise malware equally important as blocking initial access to a network, Costis says. To that end, a key detection opportunity for defenders when it comes to NeedyMantis may be the attacker’s behavior — including file copying, DLL loading, and unusual network activity — rather than merely detecting artifacts of the malware itself, Costis says.
"Adversarial exposure validation can test whether controls detect the sideloaded DLL and interrupt the kind of hands-on-keyboard deployment Microsoft observed," he says. "If they don't, the attacker has room for follow-on activity."
Another potential way to defend against NeedyMantis would be to run an organization's endpoint detection and response (EDR) in block mode in case antivirus (AV) protection does not detect the threat. "EDR in block mode works behind the scenes to remediate malicious artifacts that are detected post-breach," according to Microsoft.