NeedyMantis Malware: Microsoft Publishes Analysis of Post-Compromise Attacks

Microsoft has published a technical analysis of the modular NeedyMantis malware, which the analysis says is used after access to an environment has been obtained.

Microsoft Threat Intelligence published an analysis of the NeedyMantis malware family on September 28, 2026. The malware is used in targeted operations after access to an environment has previously been obtained. According to Microsoft, it is used to maintain long-term access and support subsequent operations.

Microsoft says the activity dates back to at least October 2025. It observed a limited number of targeted incidents involving telecommunications, universities, healthcare nonprofits, intergovernmental organizations, and government contractors. It uses the designation Storm-3069 for at least one operator.

NeedyMantis Malware Is Used After Access Is Obtained

NeedyMantis is modular malware deployed only after an attacker has gained access to an environment. According to Microsoft, it may be used to maintain access and support further operations.

The malware uses DLL sideloading, in which a legitimate program loads a malicious DLL instead of the expected component. It also uses custom encrypted and compressed archives and consists of modular components.

Microsoft did not disclose the number of affected organizations or the complete initial-access method for individual incidents. It therefore has not been confirmed that all recorded cases originated from a single operator; the malware may be used by multiple actors.

Connection to DAEMON Tools Is Not a Confirmed Distribution Route

Microsoft found a connection during a follow-up analysis of indicators from the DAEMON Tools supply-chain compromise. However, it explicitly did not confirm that NeedyMantis malware was distributed through this supply-chain attack.

Microsoft assesses the observed activity as consistent with actors operating from China, but it did not attribute Storm-3069 to a Chinese state actor.

Microsoft Publishes Indicators and Hunting Queries

Microsoft published indicators of compromise, detections, and hunting queries. Organizations should check in particular for the published hashes, suspicious DLLs in paths imitating legitimate software, and communications with the listed C2 domain.

Because NeedyMantis malware is used after access has been obtained, these checks may help identify signs of long-term access persistence in already compromised networks. This is not a new vulnerability.

Further developments may confirm additional operators or victims, new indicators of compromise, C2 infrastructure, or updated detection rules. The attribution of Storm-3069 and its relationship to the DAEMON Tools compromise may also become clearer.

Sources

  • Microsoft Security Blog – Primary technical analysis of NeedyMantis, the scope of observed targeting, the connection to Storm-3069, attribution limitations, indicators of compromise, and detection recommendations.
  • Kaspersky ICS CERT – Context on the earlier DAEMON Tools supply-chain compromise, whose indicators Microsoft used in its research.

Verified and updated: September 29, 2026 06:26

Sharing