# Microsoft details NeedyMantis malware found in targeted network intrusions

_Published Monday, September 28, 2026 at 5:08 PM EDT · Security · Latest · Tier 2 — Notable_

![Microsoft details NeedyMantis malware found in targeted network intrusions — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJgqNtFBBtX_6em5nY1VC9Q4M6HMG7gzxiQspFHsQRfQgm3LK5kTsHi-9SbwEx8kaeVv7BtKGFq3u1SmTGFEOe0z78fxFCxRFVEb09v0FMZ5tT-FNl7sUBnsGPPpDlAaQh4E_CSQQnwFakxNll2AvKiBvidb9ljEatmOzdJV4T4z8r5lmYG3DINHy-wR0/s1700-nu-rw-lo-l85-e365/hackers.jpg)

Microsoft says it found NeedyMantis malware in a small number of targeted intrusions affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations and government contractors.

The malware gives attackers who have already entered a network a way to maintain access. In cases Microsoft examined, a legitimate program loaded a malicious DLL, which unpacked further components from an encrypted archive. The main component then connected to a command-and-control server, allowing operators to load additional modules.

Microsoft published file hashes, network indicators and hunting queries for defenders. It has not confirmed what the added modules do or whether NeedyMantis is still in use.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html)

---
Canonical: https://techandbusiness.org/newswire/fG0lsUuyJEwUjsko5zvhl3
Published: 2026-09-28T21:08:34.003Z
Story chronology: 2026-09-28T18:35:42.000Z
Retrieved: 2026-09-28T23:03:08.244Z
Publisher: Tech & Business (techandbusiness.org)
