Select a theme from the list.
Insights

From our experts

Latest
Apple Closes CoreGraphics Flaw Linked to Sophisticated Targeted AttacksThousands of Supabase Databases Leak the Secrets Behind Rapid App DevelopmentNeedyMantis Gives Targeted Intruders a Modular Foothold Inside Windows NetworksSharePoint Code-Execution Flaw Moves From Patch Notes to Active AttacksLunex Leaves Security Tools Running but Blind Before Raiding BrowsersCloudflare Container Flaw Broke the Wall Between Customer WorkloadsStorm-3168 Turns Stolen Azure Identities Into a Seven-Minute WipeoutOne Encoded Character Lets Attackers Slip Past WAFs and Hit PeopleSoftClop Ransomware Gang Gets Hacked Through Its Own Outdated CMSMicrosoft Pushes Data-Loss Prevention Into the Path of Shadow AIDormant GitHub Actions Reawakened With Their Malicious Payloads IntactKiteworks Calls for Emergency Shutdown as Authorities Warn of Imminent AttacksApple Closes CoreGraphics Flaw Linked to Sophisticated Targeted AttacksThousands of Supabase Databases Leak the Secrets Behind Rapid App DevelopmentNeedyMantis Gives Targeted Intruders a Modular Foothold Inside Windows NetworksSharePoint Code-Execution Flaw Moves From Patch Notes to Active AttacksLunex Leaves Security Tools Running but Blind Before Raiding BrowsersCloudflare Container Flaw Broke the Wall Between Customer WorkloadsStorm-3168 Turns Stolen Azure Identities Into a Seven-Minute WipeoutOne Encoded Character Lets Attackers Slip Past WAFs and Hit PeopleSoftClop Ransomware Gang Gets Hacked Through Its Own Outdated CMSMicrosoft Pushes Data-Loss Prevention Into the Path of Shadow AIDormant GitHub Actions Reawakened With Their Malicious Payloads IntactKiteworks Calls for Emergency Shutdown as Authorities Warn of Imminent Attacks
Security Insight

NeedyMantis Gives Targeted Intruders a Modular Foothold Inside Windows Networks

NeedyMantis Gives Targeted Intruders a Modular Foothold Inside Windows Networks
Photo by Ann H on Pexels

Microsoft has documented NeedyMantis, a modular Windows malware framework used to preserve access after attackers have already entered a network. The selectively deployed threat uses DLL sideloading, encrypted archives and expandable components to support long-term operations against telecommunications, academic, nonprofit and government-linked organizations.

Microsoft Threat Intelligence has exposed a post-compromise malware family called NeedyMantis that appears designed for patience rather than rapid disruption. The framework has been observed in a limited number of targeted intrusions affecting telecommunications providers, universities, medical nonprofits, intergovernmental bodies and government contractors.

A Tool for Staying Inside

Unlike commodity malware distributed through mass email campaigns, NeedyMantis is generally deployed after an attacker has gained access to the victim environment. Microsoft traced related activity to at least October 2025 and identified one operator as Storm-3069, a temporary designation associated with the earlier DAEMON Tools supply chain compromise. Microsoft assesses that the observed activity originates from China, but it has not attributed the operator to a specific government organization.

The malware is packaged with legitimate software such as Poedit, curl, Vim or TightVNC. A malicious DLL is given a name expected by the genuine application, causing it to load through DLL sideloading. That loader extracts additional components from a custom encrypted and compressed archive, helping the framework resist routine inspection.

Once active, NeedyMantis establishes encrypted command communications and can receive additional modules. Microsoft has not confirmed the complete capabilities of those modules, but the architecture gives operators a flexible way to extend an intrusion without replacing the original implant.

What Defenders Should Do

  • Investigate unexpected DLL files placed beside legitimate applications.
  • Monitor administrative shares and remote execution involving tools such as Impacket.
  • Apply application control policies to prevent unapproved software from loading libraries.
  • Enable endpoint detection in blocking mode and inspect unusual WebSocket communications.
  • Use Microsoft's published indicators and hunting queries across endpoint and network telemetry.

In my view, NeedyMantis demonstrates why detecting the initial breach is not enough. Security teams must also look for quiet software bundles, abnormal library-loading relationships and tools moved through internal shares. An attacker who has already crossed the perimeter may choose malware that blends into ordinary application directories rather than something that immediately triggers a high-severity alert.

The limited targeting should not reduce concern. Selective deployment often indicates that operators are protecting a valuable capability. Organizations in the affected sectors should treat the disclosure as an opportunity to hunt proactively, particularly if they have previously investigated suspicious administrative activity or software supply chain exposure.

Talk to our team →

Latest

Apple Closes CoreGraphics Flaw Linked to Sophisticated Targeted AttacksSep 29, 2026Thousands of Supabase Databases Leak the Secrets Behind Rapid App DevelopmentSep 29, 2026NeedyMantis Gives Targeted Intruders a Modular Foothold Inside Windows NetworksSep 29, 2026SharePoint Code-Execution Flaw Moves From Patch Notes to Active AttacksSep 28, 2026Lunex Leaves Security Tools Running but Blind Before Raiding BrowsersSep 28, 2026Cloudflare Container Flaw Broke the Wall Between Customer WorkloadsSep 28, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication4Global CMS Exploitation Wave Plants Webshells on Business Websites5Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path6Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards