INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

NeedyMantis Provides Long-Term Access to Compromised Microsoft Networks

| 2026-09-28 15:56 CRITICAL HIGH CYBERATTACK (GENERAL)
Executive Summary
AI-generated
A previously unidentified malware family, dubbed "NeedyMantis," has been linked to a threat actor tracked as Storm-3069 based in China. The malware provides long-term stealth access to targeted networks once they've already infiltrated a system, revealing a potential blind spot for defenders. NeedyMantis is used by attackers in targeted intrusions against telecommunications companies, universities, medical nonprofits, intergovernmental organizations, and government contractors, with at least 5 affected entities identified. The malware communicates with attacker-controlled infrastructure over HTTPS and WebSockets, gathers information about the compromised system, and can load additional components as needed through a two-stage loader. Microsoft discovered NeedyMantis while investigating indicators of compromise associated with the DAEMON Tools supply chain compromise in May 2026; it has been used since at least October 2025.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

c82520••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
9cb68f••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
e842dd••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
co•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Salt TyphoonSalt Typhoon
Target & Sectors
GCC GCC NORTH_AMERICA NORTH_AMERICA educationeducation telecommunicationstelecommunications
Incident Timeline
‎2025/09/29
Salt Typhoon, a China-backed threat group, breached the networks of telco providers in 2025.
source_region China
infrastructure Microsoft 365
organisation Reach Microsoft 365
organisation Corporate Data Indeed
threat_actor Salt Typhoon
general_metric 365 Microsoft
‎at least October 2025
Threat actors used malware since at least October 2025 to maintain long-term access inside compromised networks.
tactic T1588.001 - Malware
organisation Cyber Security News
‎2026/09/28
Threat actors used the NeedyMantis malware in targeted intrusions against various organizations.
attribution Microsoft Threat Intelligence
industry Telecommunications
industry Government
attribution NeedyMantis
‎2026/09/28
Threat actors tracked as Storm-3069 used NeedyMantis, a modular post-compromise malware framework, to maintain long-term access and support follow-on operations in targeted intrusions involving telecommunications providers, universities, medical nonprofits, intergovernmental bodies, and government contractors.
organisation NeedyMantis
organisation Kaspersky
organisation Microsoft Security Blog
organisation Microsoft Finds New
organisation Maintain Secret Access Inside Target Networks
organisation Storm-3069
organisation Microsoft
organisation DLL
organisation WebSockets
organisation HTTPS
organisation Mass Disinformation
organisation Impacket
organisation AttackIQ
organisation Costis
organisation EDR
organisation AV
Tactical Metrics
Metrics
infrastructure
‎Microsoft 365
Affected Product