Modern cyberattacks are increasingly designed to remain hidden after an attacker has already gained access to an organization.
A recent analysis by Microsoft Threat Intelligence of a malware family called NeedyMantis highlights this evolving threat. The malware has been observed in targeted intrusions involving telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors.
The activity demonstrates an important cybersecurity lesson: preventing the initial compromise is critical, but organizations must also be prepared to detect and contain attackers who are already inside the environment.
What Is NeedyMantis?
Microsoft describes NeedyMantis as a modular post compromise malware family.
Rather than being used primarily as an initial entry tool, the malware has been observed after attackers established access to a target environment. Its design supports persistence, command and control communications, and the deployment of additional components.
Activity associated with the malware dates back to at least October 2025.
Microsoft identified the malware while investigating indicators connected to the earlier DAEMON Tools supply chain compromise. Microsoft currently tracks at least one threat actor associated with the activity as Storm 3069.
Microsoft has observed activity aligned with threat actors operating from China, but has not determined that all NeedyMantis activity is attributable to the same operator.
This distinction is important because cybersecurity investigations often evolve as additional infrastructure, malware samples, and threat actor activity are discovered.
How Attackers Can Hide Malware Inside Legitimate Software Components
One of the most notable characteristics of NeedyMantis is its use of DLL sideloading.
Attackers can package malicious DLL files alongside legitimate applications and manipulate the loading process so that the malicious component is executed when the legitimate software starts.
Microsoft observed NeedyMantis components masquerading as legitimate software libraries associated with applications and vendors.
This technique can make malicious activity more difficult to identify because the files may appear to belong to trusted software.
The malware has also been observed using legitimate software components from tools such as Poedit, curl, Vim, and TightVNC as part of its packaging.
The broader lesson is clear: security teams cannot assume that software located inside a trusted application directory is automatically safe.
A Multi Stage Malware Architecture
NeedyMantis uses several layers designed to make analysis and detection more difficult.
The malware can include:
• A first stage loader
• Encrypted and compressed custom archives
• A second stage loader
• A main malware component
• Command and control communications
• Additional downloadable modules
The components also use obfuscation and anti analysis techniques.
This layered architecture allows attackers to separate different functions and potentially make detection more difficult.
For defenders, this means endpoint security should look beyond individual files and examine the behavior and relationships between processes, DLLs, network connections, and persistence mechanisms.
Command and Control Capabilities
The malware’s main component manages communication with attacker controlled infrastructure and can support the delivery of additional modules.
Microsoft observed WebSocket based communications and encrypted traffic mechanisms.
The malware also uses configuration data that can contain command and control information, communication settings, and timing information.
This demonstrates why network monitoring remains an important layer of enterprise security.
Even when malicious files evade endpoint detection, unusual outbound connections can provide valuable indicators for security teams.
Why Post Compromise Malware Is a Major Concern
Organizations often focus heavily on preventing phishing, malware downloads, vulnerability exploitation, and other initial access techniques.
Those controls remain important, but modern intrusions frequently involve multiple stages.
Once attackers establish access, they may attempt to:
• Maintain persistence
• Escalate privileges
• Move laterally
• Collect information
• Establish command and control
• Deploy additional malware
• Target sensitive systems
• Exfiltrate data
• Disrupt business operations
Post compromise malware such as NeedyMantis is therefore particularly concerning because it can become part of a broader intrusion rather than functioning as an isolated malicious file.
Software Supply Chain Security Remains Critical
The connection between NeedyMantis research and the earlier DAEMON Tools compromise also highlights the importance of software supply chain security.
Organizations depend on thousands of third party applications, libraries, updates, drivers, plugins, and software components.
A compromise somewhere within that ecosystem can create security consequences far beyond the original software provider.
Organizations should therefore maintain visibility into:
• Approved software
• Software versions
• Third party dependencies
• Application publishers
• Digital signatures
• DLL loading behavior
• Software update mechanisms
• Endpoint activity
• Network communications
Software inventories should also be regularly reviewed so security teams can quickly determine which systems may be exposed when a new threat is identified.
What Organizations Can Do
Organizations can strengthen defenses against threats such as NeedyMantis by adopting a layered security approach.
1. Strengthen Endpoint Detection
Deploy endpoint detection and response capabilities capable of identifying suspicious DLL loading, shellcode execution, obfuscated scripts, and unusual process behavior.
2. Monitor DLL Sideloading
Security teams should investigate applications loading unexpected DLLs, particularly when the DLL is located in unusual directories or does not match the expected software version.
3. Monitor Outbound Network Connections
Organizations should monitor unusual outbound connections from endpoints and investigate communication with infrastructure associated with known threats.
4. Apply Attack Surface Reduction Controls
Security policies should restrict unnecessary script execution, suspicious executable activity, and other behaviors frequently abused by attackers.
5. Strengthen Software Supply Chain Controls
Organizations should maintain an inventory of third party applications and evaluate the security practices of critical software suppliers.
6. Conduct Threat Hunting
Threat hunting can help identify activity that traditional alert based monitoring may miss.
Security teams should investigate unusual processes, suspicious DLL relationships, unexpected persistence mechanisms, and anomalous network communications.
7. Prepare for Post Compromise Activity
Incident response plans should address what happens after an attacker gains access.
Organizations should be prepared to isolate affected endpoints, investigate identity activity, identify lateral movement, contain command and control communications, and determine whether sensitive information was accessed.
Industries That Should Pay Close Attention
Telecommunications
Telecommunications organizations operate highly connected environments and manage critical infrastructure. Security assessments, endpoint monitoring, network security testing, threat hunting, and incident response preparation can help reduce exposure to targeted intrusions.
Healthcare and Medical Organizations
Medical nonprofits, healthcare providers, and related organizations manage sensitive information and increasingly connected technology environments. COE Security can help with application security, network and cloud assessments, vulnerability management, penetration testing, and compliance focused security programs.
Universities and Research Organizations
Universities and research institutions often operate large environments with diverse users, applications, and third party software. Security monitoring, identity security, vulnerability assessments, and software supply chain reviews can help strengthen their defenses.
Government and Government Contractors
Government organizations and contractors can be attractive targets for long term intrusion campaigns. COE Security can support these organizations through penetration testing, threat detection, network and cloud security assessments, secure development consulting, and security monitoring.
Technology and Software Companies
Technology companies need strong software development and supply chain security controls. COE Security can help evaluate applications, APIs, cloud environments, dependencies, software development processes, and infrastructure security.
Conclusion
The NeedyMantis investigation highlights how modern malware can operate as part of a larger intrusion rather than simply acting as a standalone malicious program.
The use of DLL sideloading, custom packaging, obfuscation, modular components, and command and control communications demonstrates why organizations need visibility across endpoints, identities, applications, networks, and software dependencies.
The broader security lesson is that trusted software cannot automatically be treated as trusted behavior.
Organizations should continuously monitor their environments, strengthen software supply chain controls, conduct threat hunting, and prepare for attacks that continue long after the initial compromise.
Cybersecurity resilience depends not only on preventing attackers from getting in, but also on detecting them quickly when they manage to get through.
About COE Security
COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.
Our offerings include:
• AI-enhanced threat detection and real-time monitoring
• Data governance aligned with GDPR, HIPAA, and PCI DSS
• Secure model validation to guard against adversarial attacks
• Customized training to embed AI security best practices
• Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
• Secure Software Development Consulting (SSDLC)
• Customized CyberSecurity Services
COE Security also helps organizations strengthen defenses against advanced malware and post compromise activity through endpoint security assessments, threat hunting, network security assessments, software supply chain reviews, vulnerability management, application security testing, cloud security assessments, incident response readiness, and penetration testing.
For telecommunications organizations, we help assess network infrastructure, endpoints, cloud environments, applications, and critical communications systems.
For healthcare organizations, we help protect sensitive data, medical applications, connected environments, cloud infrastructure, and third party integrations while supporting regulatory requirements.
For universities and research organizations, we help strengthen identity security, endpoint protection, application security, vulnerability management, and network monitoring.
For government organizations and contractors, we help assess applications, infrastructure, cloud environments, networks, endpoints, and security monitoring capabilities while supporting compliance and cyber resilience requirements.
For technology and software companies, we help identify risks across software development environments, applications, APIs, cloud platforms, third party dependencies, and software supply chains.
Our goal is to help organizations identify security gaps, reduce cyber risk, strengthen resilience, and maintain compliance across increasingly connected digital environments.
Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption and to stay updated and cyber safe.
Click to read our LinkedIn feature article