VYPR
researchPublished Sep 28, 2026· 2 sources

NeedyMantis Malware Facilitates Post-Compromise Access for China-Linked Actors

Microsoft details NeedyMantis, a modular post-compromise malware family used by China-linked threat actors since October 2025 to maintain long-term access in targeted sectors.

Microsoft Threat Intelligence has identified NeedyMantis, a sophisticated modular post-compromise malware family that has been observed in a limited number of targeted operations since at least October 2025. This malware is typically deployed after a threat actor has already gained initial access to a target environment, indicating its primary purpose is to maintain persistent, long-term access and facilitate subsequent malicious activities.

The discovery of NeedyMantis occurred during an analysis of indicators associated with the DAEMON Tools supply chain compromise, previously reported by Kaspersky. While observed activity aligns with threat actors operating from China, Microsoft has not definitively attributed all instances to a single actor. The malware has been deployed against a range of sensitive sectors, including telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors, suggesting a selective targeting strategy rather than widespread distribution.

NeedyMantis distinguishes itself through a complex architecture that combines multiple loaders, custom encrypted file archives, a unique executable file format, and modular components. This design allows operators to effectively evade analysis and extend the malware's functionality by adding new modules as needed. The combination of these advanced evasion techniques and its use in targeted intrusions makes NeedyMantis a significant case study for understanding how adversaries establish and maintain deep access within victim networks.

Observed operations involving NeedyMantis have been linked to Storm-3069, the designation for activity associated with the DAEMON Tools supply chain compromise. While Microsoft assesses this activity originates from China, it has not been attributed to a specific nation-state actor. The malware's deployment against specific victim profiles, coupled with its sophisticated evasion capabilities, points towards a deliberate and targeted approach by its operators.

The malware's deployment typically occurs during the post-compromise stage of an intrusion. NeedyMantis is composed of multiple components written in C++ and x64 shellcode, starting with a first-stage loader and a file archive. These components are often packaged alongside legitimate software, with the loader masquerading as a required DLL and being deployed through DLL sideloading techniques. Abused legitimate software includes applications like Poedit, curl, Vim, and TightVNC, with the malware also impersonating components from Microsoft Office, Broadcom, Intel, and NVIDIA.

In one observed incident, threat actors utilized the Impacket toolkit during hands-on-keyboard activity to copy the legitimate software, the malicious DLL, and the file archive from a network share onto a targeted device. This action, performed after initial access was secured, exemplifies how NeedyMantis can be introduced into an environment to establish a more robust foothold. While supply chain compromises remain a potential vector for initial access, NeedyMantis itself has not been directly observed being distributed through such means.

Microsoft provides detailed guidance for organizations to defend against NeedyMantis and related threats. This includes specific indicators of compromise (IOCs) and Microsoft Defender detections designed to identify and block the malware. The analysis highlights the importance of robust endpoint detection and response (EDR) capabilities and vigilant monitoring for unusual DLL loading or file access patterns, especially when legitimate software is involved.

Understanding the intricate workings of malware families like NeedyMantis is crucial for cybersecurity professionals. Its modular design, advanced evasion tactics, and use in targeted operations underscore the evolving sophistication of threat actors and the persistent need for proactive defense strategies to counter advanced persistent threats.

This new report from Microsoft Threat Intelligence provides a deeper technical dive into the NeedyMantis malware framework, detailing its modular architecture and specific evasion techniques. It highlights the use of DLL sideloading with legitimate software packages and custom archive formats, as well as its communication methods via obfuscated WebSockets and a custom binary protocol. The article also notes that NeedyMantis was discovered while pivoting from indicators linked to the DAEMON Tools supply-chain compromise (Storm-3069), though it was not delivered via that specific vector.

Synthesized by Vypr AI