Close Menu
NCIJ Network NCIJ Network
    What's Hot

    This new ChatGPT scam tricks you into installing malware – how to spot the trap

    October 3, 2026

    Frontline Education breach exposes school district employee data

    October 3, 2026

    New SEC crypto rules threaten small advisers, but big firms win

    October 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • This new ChatGPT scam tricks you into installing malware – how to spot the trap
    • Frontline Education breach exposes school district employee data
    • New SEC crypto rules threaten small advisers, but big firms win
    • Satellite data reveal massive scale of routine oil pollution in oceans. See the map
    • Utilities are public services – and should not be run as businesses | Utilities
    • Was Christa Pike’s execution team all women? We investigated
    • French Unrest: Are we witnessing a new ‘Yellow Vests’ movement? – Spotlight
    • ICE Has Been Dumping Protester Photos Into a Palantir Database
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, October 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ‘NeedyMantis’ Provides Long-Term Access to Compromised Networks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 1, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A previously unidentified malware family is giving attackers long-term stealth access to targeted networks once they’ve already infiltrated a system, revealing a potential blind spot for defenders that tend to focus more on initial intrusion rather than post-compromise activity.

    The malware, dubbed “NeedyMantis,” is a modular framework that has been used in a limited number of targeted intrusions against telecommunications companies, universities, medical nonprofits, intergovernmental organizations, and government contractors, Microsoft Threat Intelligence revealed in a blog post yesterday.

    The company linked the malware to a threat actor tracked as Storm-3069 that is based in China, though Microsoft did not link the actor to any Chinese nation-state groups. However, Microsoft has not concluded that all deployments of the malware are tied to Storm-3069, the company said.

    Microsoft discovered NeedyMantis while investigating indicators of compromise (IoCs) associated with the DAEMON Tools supply chain compromise, which was reported by Kaspersky in May. The malware, used since at least October 2025, combines multiple loaders, custom encrypted file archives, a custom executable file format, and modular components that enable operators to evade analysis and extend functionality through additional modules.

    Related:Russia’s Star Blizzard Ditches ClickFix to Widen Phishing Net

    “These characteristics, combined with its use in targeted intrusions, make NeedyMantis a useful case study for understanding how threat actors establish and maintain long-term access within victim environments,” according to Microsoft Threat Intelligence.

    How NeedyMantis Works

    At its core, NeedyMantis is a modular backdoor designed for post-compromise activity, which means an attacker already must have gained initial access to a network to deploy the malware. It communicates with attacker-controlled infrastructure over HTTPS and WebSockets, gathers information about the compromised system, and can load additional components as needed.

    Distributed by a two-stage loader, NeedyMantis can make malicious code look legitimate. It uses DLL sideloading to hide behind trusted applications such as Poedit, curl, Vim, and TightVNC, with malicious DLLs posing as components from major software vendors, according to Microsoft.

    “The loader and archive have been found packaged alongside legitimate software, with the first-stage loader — masquerading as a required DLL — being loaded through DLL sideloading,” according to the post.

    The malware also can peel back layers of encrypted and compressed payloads, with its loaders using custom archives, changing encryption keys, and employing other techniques designed to make static analysis harder.

    Related:UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks

    Range of NeedyMantis Capabilities Unknown

    In one intrusion, attackers used Impacket to copy the legitimate software and malicious files before execution. “This activity occurred after the actor had already obtained access to the environment and illustrates one method by which NeedyMantis can be introduced during an intrusion post-compromise,” according to the post.

    And though Microsoft revealed some capabilities of the malware, given its modular nature, it’s likely that there are many others that remain unknown, according to Andrew Costis, engineering manager of the adversary research team at AttackIQ.

    “The question is what happens after entry,” he tells Dark Reading. “Its main component can load further modules, although their capabilities remain unconfirmed. Finding the first stage may not reveal everything an operator can do.”

    Detection Based on Behavior

    Microsoft also did not give a clear motive for Storm-3069’s use of NeedyMantis. However, given its target base, there is a high likelihood that attackers are interested in cyber-espionage activity, Costis surmises.

    “For a telecom or government contractor, I’d worry about someone quietly moving toward sensitive systems and maintaining access long enough to gather intelligence,” he says.

    Related:Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign

    Indeed, last year the China-backed threat group Salt Typhoon breached the networks of telco providers in a global spree, demonstrating that critical infrastructure providers continue to be high-value targets for nation-state actors.

    That makes detection of post-compromise malware equally important as blocking initial access to a network, Costis says. To that end, a key detection opportunity for defenders when it comes to NeedyMantis may be the attacker’s behavior — including file copying, DLL loading, and unusual network activity — rather than merely detecting artifacts of the malware itself, Costis says.

    “Adversarial exposure validation can test whether controls detect the sideloaded DLL and interrupt the kind of hands-on-keyboard deployment Microsoft observed,” he says. “If they don’t, the attacker has room for follow-on activity.”

    Another potential way to defend against NeedyMantis would be to run an organization’s endpoint detection and response (EDR) in block mode in case antivirus (AV) protection does not detect the threat. “EDR in block mode works behind the scenes to remediate malicious artifacts that are detected post-breach,” according to Microsoft.

    access Compromised longterm NeedyMantis networks
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Frontline Education breach exposes school district employee data

    Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

    In Rare Move, Alleged Iranian State Hacker Extradited to US

    Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

    Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

    Crypto Scammers Hijack Microsoft’s Official X Account

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    This new ChatGPT scam tricks you into installing malware – how to spot the trap

    October 3, 2026

    Frontline Education breach exposes school district employee data

    October 3, 2026

    New SEC crypto rules threaten small advisers, but big firms win

    October 3, 2026

    Satellite data reveal massive scale of routine oil pollution in oceans. See the map

    October 3, 2026
    Latest Posts

    Lime bikes hurtling around the city: is this the revenge of a priced-out generation? | Andy Beckett

    August 8, 2026

    Clarity Act Delayed Until September, Trump Praises Bitcoin

    August 8, 2026

    North Carolina Ports confirms cyberattack disrupting operations

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    This new ChatGPT scam tricks you into installing malware – how to spot the trap

    October 3, 2026

    Frontline Education breach exposes school district employee data

    October 3, 2026

    New SEC crypto rules threaten small advisers, but big firms win

    October 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.