Threats & Adversaries · APT / Espionage

Microsoft Finds NeedyMantis Living Past the Breach

Microsoft Threat Intelligence identified NeedyMantis, a previously unreported modular malware family, in limited targeted operations across telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors. Microsoft says the activity goes back to at least October 2025 and appears to be part of post-compromise access, not the first break-in.

NeedyMantis packages pieces in encrypted archives and uses custom loaders plus modular components, so an operator can swap in new functions without exposing one obvious payload. That design helps the malware stay hidden, maintain access, and support follow-on activity after the initial intrusion.

For organizations in the affected sectors, the exposure is whatever access the intruder already won and the later-stage activity that can ride on it. If a breach is being handled only as an entry event, this family is the reminder that the more durable problem may be the operator still inside the environment.

2 sources · 4h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-09-29

Every edition of this story: Microsoft Finds NeedyMantis Living Past the Breach

More from today