Microsoft Discovered NeedyMantis Malware Framework
The modular tool allowed operators to maintain covert access within compromised networks across diverse sectors.
Updated on Sept. 28, 2026 in Cybersecurity

Live Poll
Do you trust that your local institutions are effectively protecting your digital data from hackers?
Microsoft Threat Intelligence recently uncovered NeedyMantis, a modular malware framework used to preserve covert network access following initial compromise. Earliest recorded activity of the framework dates back to October 2025.
Why it matters
The discovery highlights the persistence tactics used in advanced network intrusions targeting high-value infrastructure. The framework was deployed to maintain unauthorized access within sectors ranging from telecommunications and academia to government contracting.
NeedyMantis functions as a modular post-compromise tool, allowing operators to persist within already-breached networks. The framework was specifically engineered for long-term covert maintenance rather than initial infiltration.
The players
Microsoft Threat Intelligence
A division of the global software giant that tracks advanced persistent threats and produces technical security forensic research.
The details
The malware operates by injecting a modular framework into a network after the initial entry phase. This modular architecture allows the software to remain functional while evading detection by standard security tools. By maintaining these covert backdoors, operators can facilitate prolonged presence within the systems of telecommunications providers, medical nonprofits, and government contractors.
Timeline
October 2025: Earliest recorded activity of NeedyMantis malware.
The Tech Race
This discovery follows the established pattern of specialized, modular persistence tools identified in the Microsoft Digital Defense Report. It underscores an ongoing race between security researchers and threat actors to isolate increasingly sophisticated, low-footprint malware.
Organizations within the telecommunications, medical, and government contracting sectors should prioritize forensic audits of historical network logs dating to October 2025. While the tool is not a consumer-facing application, its deployment indicates a need for deeper scrutiny of post-authentication network behavior.
The takeaway
The discovery of NeedyMantis serves as a reminder that covert persistence often relies on modular code that can be updated dynamically inside a network. Defenders should watch for future reports from security researchers that identify specific indicators of compromise linked to this modular framework.
Further reading
For more on evolving threat landscapes, visit our Cybersecurity section.
Live Poll
Do you trust that your local institutions are effectively protecting your digital data from hackers?







