Microsoft has published a technical analysis of a malware family called NeedyMantis, which hackers use to keep long-term access to networks they have already compromised. The backdoor has been observed in a limited set of targeted intrusions, with victims including telecommunications organizations and universities.

The malware appears designed for stealth and persistence rather than broad distribution. Microsoft's report highlights how NeedyMantis fits into post-exploitation activity, allowing attackers to remain inside a network over an extended period. Because the source is a single vendor analysis, there are no conflicting accounts to compare, but the findings align with the general pattern of targeted backdoor use in espionage-style operations.