Microsoft Details NeedyMantis Malware Used After Breaches
Microsoft says a modular malware framework called NeedyMantis has been used since at least October 2025 in a small number of targeted intrusions to maintain access to networks attackers had already breached. The activity affected telecommunications organizations, universities, medical nonprofits, intergovernmental organizations and government-related organizations, according to Microsoft Threat Intelligence. The framework is designed for use after an attacker gains entry, rather than as a means of initial access. Microsoft said it found NeedyMantis while investigating indicators connected to a separate compromise involving DAEMON Tools. The company has not observed NeedyMantis being delivered through that supply-chain incident, and said the framework was identified during follow-up analysis. Microsoft assesses that activity tracked as Storm3069 originates in China, but has not attributed the group to a Chinese state actor. It also has not determined whether all NeedyMantis deployments are associated with Storm3069 or whether multiple operators use the framework. The available analysis does not establish how attackers initially accessed the affected networks.