Threats · 3h ago
Microsoft Threat Intelligence identified NeedyMantis, a previously unreported modular malware family, in limited targeted operations across telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors. Microsoft says the activity goes back to at least October 2025 and appears to be part of post-compromise access, not the first break-in.
NeedyMantis packages pieces in encrypted archives and uses custom loaders plus modular components, so an operator can swap in new functions without exposing one obvious payload. That design helps the malware stay hidden, maintain access, and support follow-on activity after the initial intrusion.
For organizations in the affected sectors, the exposure is whatever access the intruder already won and the later-stage activity that can ride on it. If a breach is being handled only as an entry event, this family is the reminder that the more durable problem may be the operator still inside the environment.
2 sources covering this story
Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft
The malware framework uses a modular architecture and a custom executable file format for long-term persistence.
Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components to maintain long-term access and support follow-on operations.
Part of the PlainSec briefing for 2026-09-29