Microsoft Warns NeedyMantis Malware Enables Persistent Network Access
Microsoft warns China-linked NeedyMantis malware maintains persistent access in telecom, university, and government networks.
Microsoft Threat Intelligence warned on September 28 that NeedyMantis, active since at least October 2025, is a multi-component C++ and x64 shellcode framework used for long-term access after an intrusion. Campaigns have targeted telecommunications providers, universities, and government-linked organizations; Microsoft associates the activity with China and at least one operator, Storm-3069, without confirming state direction. Attackers install it through hands-on access, side-loading DLLs packaged with software such as Poedit, curl, Vim, and TightVNC or fake Microsoft, Broadcom, Intel, and NVIDIA components, then deploy a second-stage loader that contacts command-and-control for persistence, exfiltration, and additional payloads. Microsoft found no evidence it was distributed through the Daemon Tools supply-chain compromise linked to Storm-3069.