HomeRisk ManagementsMicrosoft Warns NeedyMantis Malware Allows Ongoing Network Access

Microsoft Warns NeedyMantis Malware Allows Ongoing Network Access

Published on

spot_img

New Malware Framework NeedyMantis Discovered by Microsoft Cybersecurity Researchers

In a recent analysis, cybersecurity researchers at Microsoft issued a warning regarding a newly identified malware framework known as NeedyMantis. This menacing software has been enabling attackers to infiltrate compromised networks, allowing them to operate undetected for extended periods. Such clandestine activity poses significant risks to various sectors, particularly telecommunications, educational institutions, and organizations associated with government entities.

NeedyMantis has been active since at least October 2025, according to findings presented by Microsoft Threat Intelligence in a report published on September 28, 2026. The malware operation displays sophisticated capabilities, suggesting that it is not merely a fleeting phase in cyber threats but a well-structured framework that can support long-term malicious campaigns.

Microsoft’s research indicates that the origins of NeedyMantis can be traced back to China. However, the company has refrained from definitively attributing this activity to state-sponsored threat actors. While they suspect at least one operator, known as Storm-3069, may be involved, the complexity and varied nature of the operations make it challenging to ascertain the full extent of the perpetrators’ affiliations.

According to Microsoft’s analysis, NeedyMantis operates in a nuanced manner; the malware is deployed only after an initial breach has occurred, allowing the attackers to establish sustained access to the compromised network. Although the exact methods through which the initial access is achieved remain a mystery, the operational dynamics of NeedyMantis are becoming clearer. Researchers have noted that the malware comprises multiple components developed in C++ and employs x64 shellcode.

A particularly alarming aspect of NeedyMantis is its deployment method, which involves leveraging legitimate software to mask its malicious activities. Microsoft identified several open-source programs, including Poedit, curl, Vim, and TightVNC, as vehicles for delivering the malware. Moreover, components posing as authentic DLL files from reputable companies such as Microsoft Office, Broadcom, Intel, and NVIDIA have also been utilized in these attacks.

The mechanics of the malware’s installation process are intricate. The attackers gain hands-on remote access to the compromised systems and manually install the malware components. This tactic aims to blend malicious activities with the normal installation processes of open-source software, making detection by cybersecurity defenses exceedingly difficult. The malware includes advanced anti-analysis features designed specifically to evade detection by security tools, ensuring that the attackers can operate with relative impunity.

Once NeedyMantis is embedded in a compromised network, a second-stage loader is executed, cementing its presence even further. In the final stage, the malware establishes a connection with a command and control server. This is critical as it allows the attacker not only persistent access to the infected machine but also enables the exfiltration of sensitive data and the installation of additional malicious components as needed.

Interestingly, while Storm-3069 has been linked to previous supply chain compromises such as the Daemon Tools incident, Microsoft has not found definitive evidence indicating that NeedyMantis itself was distributed through similar supply chain methods. Nevertheless, the potential for supply chain vulnerabilities remains a viable entry point for cyber actors attempting to deploy such malware.

To bolster defenses against the evolving threat posed by NeedyMantis, Microsoft has issued a series of recommended mitigations for organizations. These strategies include activating cloud-delivered protection to swiftly identify and neutralize new malware variants, operating Endpoint Detection and Response (EDR) in block mode to prevent the execution of malicious files, and enabling network protection features within Microsoft Defender for Endpoint.

Additionally, organizations are advised to configure automatic attack disruption measures within Microsoft Defender XDR, further enhancing their security posture against possible incursions facilitated by frameworks like NeedyMantis.

In conclusion, the emergence of NeedyMantis underscores the continual evolution of cyber threats. As attackers become increasingly adept at leveraging legitimate tools for malicious purposes, vigilance and proactive defenses will be essential for protecting sensitive information and maintaining the integrity of compromised networks.

Source link

Latest articles

OpenAI Discontinues GPT-6.1 Astra Amid Concerns Over Agent Misconduct

In a recent statement regarding a significant cybersecurity incident, Aviv Nahum, the co-founder and...

When the Ransom Note Appears, the Room Divides in Half

Why Documented Recovery Testing Outweighs Every Ransomware Assurance Claim Made On the night of September...

Cyber Briefing – September 29, 2026: CyberMaterial

Cybersecurity Threats Evolve: Custom GPTs, Japan Cyber Attacks, and More In recent developments within the...

When AI Agents Gain More Authority

Agentic AI, ...

More like this

OpenAI Discontinues GPT-6.1 Astra Amid Concerns Over Agent Misconduct

In a recent statement regarding a significant cybersecurity incident, Aviv Nahum, the co-founder and...

When the Ransom Note Appears, the Room Divides in Half

Why Documented Recovery Testing Outweighs Every Ransomware Assurance Claim Made On the night of September...

Cyber Briefing – September 29, 2026: CyberMaterial

Cybersecurity Threats Evolve: Custom GPTs, Japan Cyber Attacks, and More In recent developments within the...