Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
Sep 28, 2026
Cyber Attack / Threat Intelligence
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use goes back to at least October 2025. Microsoft found NeedyMantis while following up on indicators from Kaspersky's investigation into the supply chain attack on DAEMON Tools . In that attack, official, signed installers for the DAEMON Tools Lite disk image program carried malicious code from April 8, 2026. The developer replaced them with a clean version on May 5. Microsoft tracks the activity tied to that attack as Storm-3069. It says Storm-3069 is one group that uses NeedyMantis, though it has not seen the malware itself spread through a supply chain attack. Defenders can check their networks using the fi...