Severity: ElevatedAction: Be aware

NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components to maintain long-term access and support follow-on operations.

Excerpt from the primary source: Microsoft Security Blog & MSRC

Who is affected

Security professionals

What you should do · Be aware

No immediate action is indicated. Share this with the relevant teams and watch for updates.

Automated guidance based on this story's classification. Check the linked advisories for specifics.

Sources

We link to original and authoritative sources. Headlines and excerpts belong to their publishers.

Vendor advisory

NeedyMantis: Unpacking a post-compromise malware family used in targeted operations Microsoft Security Blog & MSRC · microsoft.com · Sep 28, 2026 · Primary source