#NeedyMantis
Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware family used in a limited number of targeted operations. Observed activity has thus far aligned with activity Microsoft associates with threat actors operating from China. msft.it/63320acEdK
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations | Microsoft Security Blog
Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components to maintain long-term access and support follow-on operations.
msft.it
September 28, 2026 at 3:02 PM
NeedyMantisは、通信、大学、医療、政府組織などのネットワークに長期アクセスを維持するマルウェア。
Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
NeedyMantis maintains long-term access in targeted intrusions, using DLL sideloading and HTTPS-to-WebSocket command-and-control.
thehackernews.com
September 28, 2026 at 9:12 PM
Microsoft Identifies NeedyMantis Malware Used for Persistent Network Access

Microsoft Threat Intelligence has identified NeedyMantis, a stealthy malware framework used by Chinese-linked actors to maintain persistent access in telecommunications, academic, and government networks.
Microsoft Identifies NeedyMantis Malware Used for Persistent Network Access
Microsoft Threat Intelligence has identified NeedyMantis, a stealthy malware framework used by Chinese-linked actors to maintain persistent access in telecommunications, academic, and government networks.
privacyneedle.com
September 29, 2026 at 1:34 PM
'NeedyMantis' Provides Long-Term Access to Compromised Networks
'NeedyMantis' Provides Long-Term Access to Compromised Networks
Microsoft observed a China-based actor using a previously unidentified malware framework in targeted intrusions against telcos, universities, medical, and government-related organizations.
www.darkreading.com
September 29, 2026 at 3:58 PM
Microsoft maps NeedyMantis persistence via DLL sideloading. Explorer can freeze copying Video CDs. SageThumbs 2K 3.4.0 fixes OneDrive thumbnails. Flyoobe 3.03.100 adds setup rating. Teams can block AI note bots. +25 more stories
Microsoft Details NeedyMantis Windows Backdoor: DLL Sideloading Detection and Hunting
Microsoft Threat Intelligence has published a detailed analysis of NeedyMantis, a modular malware family that attackers install after they are already inside a network. Its main purpose is to keep…
windowsforum.com
September 28, 2026 at 6:00 PM
Microsoft found NeedyMantis in targeted attacks on organizations, but hasn’t confirmed whether it’s still in use.

The DAEMON Tools Lite installer ta…

https://en.hacks.gr/tilepikoinonies-panepistimia-kai-foreis-ygeias-sto-stochastro-epitheseon-me-needymantis/

#NeedyMantis #DAEMONToolsLite #Malware
September 29, 2026 at 10:47 AM
Microsoft’s NeedyMantis research is a reminder that the harder security problem often starts after initial access.

The issue is whether your architecture can detect persistence, deployment, and operator behaviour once the attacker is already inside.

themicrosoftcloudblog.com/2026/09/need...
NeedyMantis Shows Why Security Architecture Has to Assume the Attacker Is Already Inside
Microsoft’s write-up on NeedyMantis is a reminder that the harder security problem often starts after initial access. This is less about one malware family and more about whether your architecture can...
themicrosoftcloudblog.com
September 29, 2026 at 12:49 PM
Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html

#CyberSecurity #InfoSec
September 29, 2026 at 1:00 AM
NeedyMantis is typically deployed after access has already been established, suggesting it is used to maintain long-term access and support follow-on operations for selective intrusions rather than gain an initial foothold.
September 28, 2026 at 3:04 PM
New discovery: NeedyMantis malware gives covert post-breach access via DLL sideloading & custom C2. #NeedyMantis #Malware #Potatosecurity #PostCompromise #ThreatIntel #NetworkSecurity thedailytechfeed.com/microsoft-un...
September 28, 2026 at 4:57 PM
New discovery: NeedyMantis malware gives covert post-breach access via DLL sideloading & custom C2. #NeedyMantis #Malware #Cybersecurity #PostCompromise #ThreatIntel #NetworkSecurity thedailytechfeed.com/microsoft-un...
September 28, 2026 at 4:57 PM
Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks: thehackernews.com/2026/09/hack...
Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
NeedyMantis maintains long-term access in targeted intrusions, using DLL sideloading and HTTPS-to-WebSocket command-and-control.
thehackernews.com
September 28, 2026 at 11:13 PM
Storm-3069 used NeedyMantis to squat inside breached enterprise networks via DAEMON Tools. Just another Tuesday in IT where trusted software works against us.

#NeedyMantis #WhyEvenBother
September 29, 2026 at 6:33 AM
Microsoft Dissects NeedyMantis Malware Used in Daemon Tools Attacks

Microsoft has detailed the NeedyMantis malware framework, used by China-based actors to maintain long-term access following the Daemon Tools supply chain attack.
Microsoft Dissects NeedyMantis Malware Used in Daemon Tools Attacks
Microsoft has detailed the NeedyMantis malware framework, used by China-based actors to maintain long-term access following the Daemon Tools supply chain attack.
privacyneedle.com
September 29, 2026 at 9:54 AM
NeedyMantis is a modular post-compromise malware identified by Microsoft Threat Intelligence, primarily targeting telecommunications, universities, and government contractors.
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
www.microsoft.com
September 29, 2026 at 1:47 PM
Microsoft names the later-stage tool: NeedyMantis.

In one intrusion, an operator copied legitimate software, a malicious DLL and an archive after access. Microsoft has not seen NeedyMantis delivered via compromised installers.
September 29, 2026 at 3:05 PM
NeedyMantis Exposes APT Post-Compromise Arsenal: Permanent Access via DLL Sideloading
NeedyMantis Exposes APT Post-Compromise Arsenal: Permanent Access via DLL Sideloading
Microsoft Threat Intelligence has disclosed NeedyMantis, a modular post-compromise malware framework active since at least October 2025 that uses DLL sideloading on legitimate software to maintain persistent access in targeted networks.
deafnews.it
September 28, 2026 at 8:16 PM
Microsoft Warns NeedyMantis Malware Enables Persistent Network Access

Researchers attribute it to a Chinese operation, but they don't go as far to link it to the Chinese state... 👀

www.infosecurity-magazine.com/news/microso...
Microsoft Warns NeedyMantis Malware Enables Persistent Network Access
Microsoft Threat Intelligence warns that NeedyMantis threat actor from China has targeted organizations across a range of industries
www.infosecurity-magazine.com
September 29, 2026 at 1:41 PM
Microsoft analysiert NeedyMantis: Die modulare Windows-Malware versteckt sich hinter legitimen Anwendungen und kann zusätzliche Funktionen nachladen.
So funktioniert der Angriff und so schützt Du Windows-Systeme:
www.windows-faq.de/2026/09/29/n...
#Windows #Security #MicrosoftDefender
NeedyMantis: Microsoft warnt vor neuer modularer Windows-Malware
Microsoft analysiert NeedyMantis, eine modulare Windows-Malware für langfristigen Netzwerkzugriff. So funktioniert der Angriff und so schützt Du Systeme.
www.windows-faq.de
September 29, 2026 at 10:21 AM
🖲️ #Noticia #CiberSeguridad #Cybersecurity #CiberNoticia

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

Leer Más / Read More...
Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
Haz clic para acceder al contenido completo.
thehackernews.com
September 29, 2026 at 12:19 AM
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
https://go.rodtrent.com/go/78ptc54
September 29, 2026 at 10:00 AM