Malware Family NeedyMantis Used to Maintain Long-Term Access to Breached Networks
Hackers have been using malware called NeedyMantis to maintain long-term access to networks they've already breached, according to Microsoft. The company said it's seen the malware used in a small number of targeted intrusions at various organizations, including telecommunications companies, universities, medical nonprofits, and government contractors.
NeedyMantis arrives as a bundle of three parts: a legitimate program, a malicious DLL file with a name similar to one loaded by that program, and an encrypted archive. When the legitimate program starts, it loads the malicious DLL through a process called DLL sideloading, which is when a program uses a library from another application.
Microsoft has identified two versions of NeedyMantis: one seen in October 2025 and another in May 2026. In both cases, the malware connects to a command-and-control (C2) server over HTTPS and then switches to a WebSocket connection. Through this connection, operators can load and unload extra modules and send data to them.
Microsoft has not confirmed what those modules do or who is behind the use of NeedyMantis, but it notes that all the activity seen so far fits the pattern of groups linked to China. The company assesses that Storm-3069, which is a group Microsoft tracks, appears to originate from China, but it has not tied the group to a Chinese nation-state actor.
Microsoft has published indicators of compromise for NeedyMantis, including file hashes and domains used by the malware. It recommends checking networks for these indicators and advises users to check outbound traffic for connections to the C2 domain. The company also suggests several Defender settings that can help detect and block NeedyMantis.