Site icon VMVirtualMachine.com

Microsoft Warns NeedyMantis Malware Enables Persistent Network Access

Microsoft Warns NeedyMantis Malware Enables Persistent Network Access

By Danny Palmer
Publication Date: 2026-09-29 13:30:00

Cybersecurity researchers at Microsoft have warned that a stealthy new malware framework is enabling attackers to remain hidden inside compromised networks for extended periods.

Dubbed NeedyMantis, the malware operation has been active since at least October 2025.

Microsoft Threat Intelligence said in analysis, published on September 28, that the malware has been used in hacking campaigns which have targeted telecommunications providers, universities and government-linked organizations.

Microsoft attributed NeedyMantis activity as emerging from China, although the company has not gone so far as to attribute the activity to the threat actor working on behalf of the Chinese state. It could also not determine if all activity could be attributed to the same operator but at least one is Storm-3069.

Microsoft’s analysis of NeedyMantis suggested that it is only deployed after the threat actor has previously gained access to the compromised environment, therefore the malware is…

Exit mobile version