NeedyMantis persistent-access malware framework
Malware Activity
Summary
Hide ▲
Show ▼
The NeedyMantis malware framework is enabling persistent access inside compromised networks, giving attackers a hidden foothold for follow-on operations and data theft. It has been active since at least October 2025 and has been used against telecommunications providers, universities, and government-linked organizations. The malware is deployed only after attackers already have access, then uses DLL side-loading and staged loaders to hide inside legitimate software. Its command-and-control stage can support data exfiltration or the installation of additional components.
Related Happenings
NeedyMantis long-term access activity
Malware Activity
H score22
First: 28.09.2026 21:35
Last: 28.09.2026 21:35
Sources 1
How related:
Dubbed NeedyMantis, the malware operation has been active since at least October 2025.
About this happening:
The NeedyMantis malware family is being used to maintain long-term access in already breached networks, affecting a small number of targeted intrusions across telecomm...
NeedyMantis long-term access activity
Malware ActivityHow related: Dubbed NeedyMantis, the malware operation has been active since at least October 2025.
About this happening: The NeedyMantis malware family is being used to maintain long-term access in already breached networks, affecting a small number of targeted intrusions across telecomm...
Latest development: 29.09.2026 16:30
Microsoft said NeedyMantis has been active since at least October 2025 and is used against telecommunications providers, universities and government-linked organizations; the malware is deployed after initial access to maintain long-term access, is installed through DLL side-loading with legitimate software such as Poedit, curl, Vim and TightVNC, and Microsoft attributed the activity as emerging from China while noting at least one operator is Storm-3069.
Psychedelic Stealer / LunexStealer MaaS infostealer deployment
Malware Activity
H score29
First: 26.09.2026 21:22
Last: 26.09.2026 21:22
Sources 1
About this happening:
Psychedelic Stealer / LunexStealer is being deployed through the Lunex MaaS platform to steal Chromium browser credentials and cryptocurrency wallet data while kee...
Psychedelic Stealer / LunexStealer MaaS infostealer deployment
Malware ActivityAbout this happening: Psychedelic Stealer / LunexStealer is being deployed through the Lunex MaaS platform to steal Chromium browser credentials and cryptocurrency wallet data while kee...
HoneyMyte PlugX campaign targeting Myanmar
Campaign
H score32
First: 14.08.2026 16:08
Last: 14.08.2026 16:08
Sources 1
About this happening:
The HoneyMyte campaign targeting Myanmar now uses PlugX to deploy CoolClient and persistence steps that make post-compromise access harder to detect. The activity...
HoneyMyte PlugX campaign targeting Myanmar
CampaignAbout this happening: The HoneyMyte campaign targeting Myanmar now uses PlugX to deploy CoolClient and persistence steps that make post-compromise access harder to detect. The activity...
UNC5221 Brickstorm, Plenet, and AgentPSD access-maintenance malware activity
Malware Activity
H score16
First: 05.06.2026 21:09
Last: 05.06.2026 21:09
Sources 1
About this happening:
The Brickstorm malware set enabled UNC5221 / VerdantBamboo to keep long-term access inside victim infrastructure, including Microsoft 365, raising the risk of stealthy...
UNC5221 Brickstorm, Plenet, and AgentPSD access-maintenance malware activity
Malware ActivityAbout this happening: The Brickstorm malware set enabled UNC5221 / VerdantBamboo to keep long-term access inside victim infrastructure, including Microsoft 365, raising the risk of stealthy...
GPU cryptomining malware using ScreenConnect and SEO poisoning
Malware Activity
H score16
First: 28.05.2026 00:31
Last: 28.05.2026 00:31
Sources 1
About this happening:
A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...
GPU cryptomining malware using ScreenConnect and SEO poisoning
Malware ActivityAbout this happening: A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...
Timeline
-
28.09.2026 03:00 2 articles · 1d ago
Microsoft warns that NeedyMantis maintains persistent access inside compromised networks
Initial DisclosureMicrosoft Threat Intelligence warned that NeedyMantis is a stealthy malware framework that has been active since at least October 2025 and is being used against telecommunications providers, universities, and government-linked organizations. Microsoft said the activity appears to emerge from China and may involve Storm-3069, and that NeedyMantis is typically deployed only after attackers already have access to the compromised environment. The framework uses C++ and x64 shellcode components, DLL side-loading with legitimate software such as Poedit, curl, Vim and TightVNC, fake Microsoft Office, Broadcom, Intel and NVIDIA DLL components, anti-analysis techniques, a second-stage loader, and command-and-control contact that preserves persistent access and can support data exfiltration or additional payload installation.
Show sources
- Microsoft Warns NeedyMantis Malware Enables Persistent Network Access — www.infosecurity-magazine.com — 29.09.2026 16:30
- Microsoft Warns NeedyMantis Malware Enables Persistent Network Access — www.infosecurity-magazine.com — 29.09.2026 16:30