Active since at least October 2025, the NeedyMantis framework is a stealthy, multi-stage malware operation that Microsoft Threat Intelligence says is being used to maintain prolonged, covert access inside compromised networks.
NeedyMantis overview and targets
Microsoft Threat Intelligence, in analysis published on September 28, described NeedyMantis as a malware operation that has been used in hacking campaigns targeting telecommunications providers, universities and government-linked organizations. The company attributed the activity as emerging from China but explicitly stopped short of saying the activity was directed by the Chinese state. Microsoft also said it could not determine whether all observed activity came from the same operator; at least one operator involved is identified as Storm-3069.
Delivery method: open-source software and DLL side-loading
According to Microsoft, attackers have packaged NeedyMantis components alongside legitimate open-source software downloads to disguise malicious installations. Examples Microsoft named include Poedit, curl, Vim and TightVNC. In other cases, elements used in NeedyMantis operations posed as fake DLL components tied to recognizable vendors and products, including Microsoft Office, Broadcom, Intel and NVIDIA. Microsoft stated the malware installs through DLL side-loading as part of a first-stage loader.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildTechnical composition and multi-stage persistence
Microsoft’s analysis shows NeedyMantis is composed of multiple components written in C++ and x64 shellcode. The company reported a sequence in which attackers with pre-existing access install the first-stage loader via DLL side-loading; they then deploy a second-stage loader to further embed the framework in the network. The final stage establishes contact with a command-and-control server that provides persistent access to the infected machine and allows exfiltration or installation of additional components. Microsoft also noted that the malware contains anti-analysis techniques designed to hinder detection by security products and investigators.
Attribution nuance and the supply chain question
Microsoft attributed the activity as emerging from China, and linked at least one operator to Storm-3069, which has been associated with the Daemon Tools supply chain compromise. Microsoft said it found no evidence that NeedyMantis itself has been distributed via that supply chain incident. The company cautioned, however, that “Supply chain activity remains one possible means by which an actor could gain the access necessary to deploy the malware.”
What this means for telecommunications providers, universities, and open-source software users
- Telecommunications providers: As named targets, these organizations should assume risk of long-term covert access and prioritize detection of unusual DLL loads and post-compromise persistence mechanisms.
- Universities: Given their inclusion among targets, academic networks should watch for downloads of commonly used open-source tools being used as a vector for side-loading and validate software integrity before deployment.
- Open-source software users and maintainers: Users who download binaries or installers for Poedit, curl, Vim, TightVNC and similar tools should verify sources and checksums; maintainers should be aware that legitimate packaging can be abused to camouflage malicious loaders.
Microsoft’s recommended mitigations
Microsoft’s published guidance focuses on leveraging its defensive capabilities to reduce exposure to NeedyMantis-style operations. Recommendations include:
- Turn on cloud-delivered protection and block at first sight to rapidly identify and block new and unknown malware variants.
- Run Endpoint Detection and Response (EDR) in block mode so that Microsoft Defender for Endpoint can block malicious artifacts.
- Enable network protection in Microsoft Defender for Endpoint.
- Configure automatic attack disruption in Microsoft Defender XDR.
Microsoft’s findings paint a picture of a threat actor that prefers to operate after gaining footholds rather than relying on a single exploit to force entry. The company explicitly notes it does not know how initial access is achieved in all cases, which leaves a critical gap: defenders must harden both access controls and post-compromise detection. For the named targets — telecommunications providers, universities and government-linked organizations — that combination of stealthy persistence, delivery alongside trusted software, and anti-analysis measures suggests the priority should be rapid detection of anomalous DLL activity and rigorous validation of software sources.
The analysis by Microsoft Threat Intelligence, published on September 28, provides specific technical markers and a set of mitigations that organizations running Microsoft Defender technologies can implement immediately. It also leaves open the larger operational questions: who exactly controls all observed NeedyMantis activity, how initial access is typically obtained, and whether other distribution avenues, including supply-chain vectors, will be used in the future. For now, the concrete steps Microsoft recommends offer the clearest path to reducing the attack surface and limiting the time an operator can remain hidden.
Original reporting: https://www.infosecurity-magazine.com/news/microsoft-needymantis-malware/




