NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
Microsoft details NeedyMantis, modular post-compromise malware used in targeted intrusions linked to China-based operators.
Microsoft Threat Intelligence disclosed NeedyMantis, a modular post-compromise malware family written in C++ and x64 shellcode and seen in a limited set of targeted intrusions since at least October 2025. Victims include telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. One known operator is Storm-3069, Microsoft’s designator for activity tied to the DAEMON Tools supply-chain compromise previously reported by Kaspersky; Microsoft assesses a China nexus but has not attributed the group to a nation-state or confirmed a single operator. The malware is typically deployed after access is already obtained, using DLL sideloading of legitimate software such as Poedit, curl, Vim, and TightVNC, plus masqueraded Microsoft, Broadcom, Intel, and NVIDIA DLLs.