Find notable cyber news and cases, enriched with sources, timelines, and signals.

NeedyMantis persistent-access malware framework

Malware Activity
First reported
Last updated
Happening score
H score 23
1 unique sources, 1 articles

Summary

Hide ▲

The NeedyMantis malware framework is enabling persistent access inside compromised networks, giving attackers a hidden foothold for follow-on operations and data theft. It has been active since at least October 2025 and has been used against telecommunications providers, universities, and government-linked organizations. The malware is deployed only after attackers already have access, then uses DLL side-loading and staged loaders to hide inside legitimate software. Its command-and-control stage can support data exfiltration or the installation of additional components.

Related Happenings

NeedyMantis long-term access activity

Malware Activity
H score22 First: 28.09.2026 21:35 Last: 28.09.2026 21:35 Sources 1

How related: Dubbed NeedyMantis, the malware operation has been active since at least October 2025.

About this happening: The NeedyMantis malware family is being used to maintain long-term access in already breached networks, affecting a small number of targeted intrusions across telecomm...

Latest development: 29.09.2026 16:30

Microsoft said NeedyMantis has been active since at least October 2025 and is used against telecommunications providers, universities and government-linked organizations; the malware is deployed after initial access to maintain long-term access, is installed through DLL side-loading with legitimate software such as Poedit, curl, Vim and TightVNC, and Microsoft attributed the activity as emerging from China while noting at least one operator is Storm-3069.

Psychedelic Stealer / LunexStealer MaaS infostealer deployment

Malware Activity
H score29 First: 26.09.2026 21:22 Last: 26.09.2026 21:22 Sources 1

About this happening: Psychedelic Stealer / LunexStealer is being deployed through the Lunex MaaS platform to steal Chromium browser credentials and cryptocurrency wallet data while kee...

HoneyMyte PlugX campaign targeting Myanmar

Campaign
H score32 First: 14.08.2026 16:08 Last: 14.08.2026 16:08 Sources 1

About this happening: The HoneyMyte campaign targeting Myanmar now uses PlugX to deploy CoolClient and persistence steps that make post-compromise access harder to detect. The activity...

UNC5221 Brickstorm, Plenet, and AgentPSD access-maintenance malware activity

Malware Activity
H score16 First: 05.06.2026 21:09 Last: 05.06.2026 21:09 Sources 1

About this happening: The Brickstorm malware set enabled UNC5221 / VerdantBamboo to keep long-term access inside victim infrastructure, including Microsoft 365, raising the risk of stealthy...

GPU cryptomining malware using ScreenConnect and SEO poisoning

Malware Activity
H score16 First: 28.05.2026 00:31 Last: 28.05.2026 00:31 Sources 1

About this happening: A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...

Timeline

  1. 28.09.2026 03:00 2 articles · 1d ago

    Microsoft warns that NeedyMantis maintains persistent access inside compromised networks

    Initial Disclosure

    Microsoft Threat Intelligence warned that NeedyMantis is a stealthy malware framework that has been active since at least October 2025 and is being used against telecommunications providers, universities, and government-linked organizations. Microsoft said the activity appears to emerge from China and may involve Storm-3069, and that NeedyMantis is typically deployed only after attackers already have access to the compromised environment. The framework uses C++ and x64 shellcode components, DLL side-loading with legitimate software such as Poedit, curl, Vim and TightVNC, fake Microsoft Office, Broadcom, Intel and NVIDIA DLL components, anti-analysis techniques, a second-stage loader, and command-and-control contact that preserves persistent access and can support data exfiltration or additional payload installation.

    Show sources