Skip to content
NeedyMantis Malware Discovered in Targeted Operations

NeedyMantis Malware Discovered in Targeted Operations

First seen 28 Sep 2026, 18:19 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 19:12 UTC

Microsoft Threat Intelligence has identified NeedyMantis, a modular post-compromise malware family, used in targeted operations against telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. The malware has been active since at least October 2025 and is typically deployed after threat actors gain initial access to a network. Microsoft linked NeedyMantis to the DAEMON Tools supply chain compromise but clarified that it has not been spread through this method. The malware is associated with threat actors operating from China, specifically a group designated as Storm-3069, though not all activity can be attributed to a single actor. NeedyMantis utilizes sophisticated techniques such as DLL sideloading and modular components to evade detection and maintain long-term access. Microsoft has provided indicators of compromise (IOCs) and mitigation guidance to help organizations defend against this threat.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-28
Microsoft discloses NeedyMantis malware
Microsoft Threat Intelligence identified NeedyMantis, a modular malware used in targeted operations against various sectors.
Microsoft

More articles in this cluster (2)

Following this threat?

Track Storm-3069, NeedyMantis and Daemon Tools in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed