Microsoft Threat Intelligence is warning that a newly detailed malware family dubbed NeedyMantis is being deployed in targeted intrusions to give attackers long-term, covert access to victim networks after an initial breach has already occurred[1][2]. The company says the post-compromise framework has been observed in a limited but diverse set of operations and that any detection of NeedyMantis should be treated as evidence of a deeper compromise rather than an isolated malware incident[1][2].
NeedyMantis is described as a modular post-compromise malware framework that combines custom loaders, encrypted archives and extensible components to preserve and extend access once attackers are inside a target environment[1][6][10]. Microsoft reports that activity linked to the malware dates back to at least October 2025 and surfaced during investigations into indicators associated with the DAEMON Tools supply-chain compromise, underscoring that NeedyMantis is part of a broader toolkit used in complex campaigns rather than a mass commodity threat[5][9][11]. No specific vulnerability or CVE is tied to NeedyMantis itself; instead, it is deployed after intruders gain access through separate intrusion vectors[1][4][9].
The campaigns documented so far have hit telecommunications providers, government contractors, universities, medical nonprofits and intergovernmental organizations, suggesting an intelligence-gathering focus rather than purely financial crime[1][9]. Microsoft tracks the actor using NeedyMantis under the designation Storm-3069 and assesses it as a China-nexus threat cluster, though it has stopped short of formally attributing the activity to a particular state entity or government sponsor[3][11][13]. Other research groups echo that assessment, describing Storm-3069 as a suspected China-linked advanced persistent threat using NeedyMantis to quietly maintain footholds in high-value networks over extended periods[11][13].
Technically, NeedyMantis relies heavily on DLL sideloading into legitimate Windows applications, planting its components alongside trusted executables so that malicious code is loaded under the guise of routine software activity[5][9][15]. Hunting guidance from Microsoft and partner research highlights altered DLLs and loader files in directories associated with tools such as Poedit, curl, Vim, TightVNC, Microsoft Office and applications branded Broadcom, Intel and NVIDIA, among others[5][9][15]. The malware also uses custom command-and-control infrastructure, including outbound connections to a domain identified as corp.tripswithengine[.]com, and has been seen communicating with a suspicious Firefox/21.0 user agent string to blend into benign traffic patterns[1][5][9].
Once deployed, NeedyMantis provides operators with mechanisms to maintain persistence, move laterally and stage follow-on activities, while remaining difficult to spot in traditional antivirus telemetry[1][2][4]. Microsoft has published multiple detection names within Microsoft Defender, including families such as TrojanDropper:Win64/NeedyMantis and behavior-based alerts tied to DLL sideloading and Impacket usage, but stresses that the presence of the framework should trigger a full incident investigation into how attackers gained initial access, what credentials or systems they have touched and whether additional tooling is present[2][4][15]. Because NeedyMantis appears only after compromise, its discovery is a late-stage signal that the environment has likely been under adversary control for some time[2][4][9].
Defenders are being urged to step up hunting and hardening rather than looking for a single patch to fix the problem. Microsoft recommends scrutinizing egress traffic for connections to the NeedyMantis command-and-control domain, investigating any unusual DLL loads from nonstandard application folders and searching logs for the suspicious Firefox/21.0 user agent associated with the malware’s activity[1][5][9]. Organizations should also enable cloud-delivered protection, “block at first sight,” network protection, endpoint detection and response in block mode, and attack-surface-reduction rules that block low-reputation executables and obfuscated or dynamically generated scripts, all of which can help detect or stop NeedyMantis components and similar post-compromise tooling before they entrench themselves further[1][2][4]. In environments where NeedyMantis indicators are found, security teams are advised to treat the incident as a high-priority intrusion, conduct comprehensive threat hunting across identity, endpoint and network layers, and consider engaging incident response specialists to fully scope and remediate the breach[2][4][9].
References
- NeedyMantis: Unpacking a post-compromise malware …
- Microsoft Finds New Malware Used by Hackers to Maintain Secret Access Inside Target Networks
- Microsoft Warns NeedyMantis Malware Enables Persistent Network Access
- Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
- DLL Sideloading Detection and Hunting
- Mitigation And Protection…
- Microsoft Tracks NeedyMantis Post-Compromise Malware Targeting Telecoms and Government Contractors
- www.microsoft.com › blog › topicThreat intelligence | Microsoft Security Blog
- aviatrix.ai · threat-research-center · needymantis-storm-3069NeedyMantis Malware: Storm-3069 APT Campaign Analysis 2026
- Government Administration Cyber Threats & Breach Reports
- needymantis