NeedyMantis: The Hidden Malware That Moves In After the Break-In

Microsoft has named a previously unknown malware family being used against telecoms, universities, and government contractors. The group behind it is linked to China. And once it's inside a network, it's built to stay quiet.

ThreatVectr Newsdesk· Editor: Lee Brown· 4 min read
Macro photograph of green circuit board traces glowing faintly in low light, with one section subtly illuminated in amber suggesting a hidden active signal bene
Share

Key points

  • Microsoft Threat Intelligence named NeedyMantis, a previously unknown malware family, in a September 28 advisory covering targeted attacks on telecoms, universities, medical nonprofits, intergovernmental organisations, and government contractors.
  • Activity dates back to at least October 2025 and was uncovered while Microsoft was investigating the DAEMON Tools supply chain attack, which Kaspersky first reported.
  • Microsoft links NeedyMantis activity to hackers operating from China, tracked internally as Storm-3069, though the company says it cannot confirm a single operator is behind every observed deployment.
  • The malware is deployed only after attackers have already broken into a network, making it a tool for maintaining access rather than gaining it.
  • Microsoft recommends running endpoint detection and response software in block mode as a defensive measure.

A new piece of malicious software, named NeedyMantis by Microsoft researchers, is designed to do one thing unusually well: stay hidden inside a network long after the initial break-in. Microsoft Threat Intelligence published its full technical writeup on September 28, 2026.

Who is behind it?

Microsoft links the observed activity to Storm-3069, a group the company assesses is operating from China. That said, Microsoft has not tied Storm-3069 to any specific Chinese government body, and it stops short of saying every NeedyMantis deployment so far is the work of a single operator.

The targets fit a familiar pattern for suspected Chinese espionage operations: telecommunications companies, universities, medical nonprofits, intergovernmental organisations, and government contractors. Microsoft has not named specific victims. No ransom demands have been reported; the assessed motive is quiet intelligence-gathering.

How does the malware work?

NeedyMantis is a "modular backdoor," meaning it is a framework with swappable parts rather than a single fixed program. Attackers install it only after they have already found a way into a target's systems through some other means. Once in, it connects back to attacker-controlled servers using HTTPS (the same encrypted web traffic your browser uses) and WebSockets (a method for keeping a live, two-way data channel open). That makes its traffic harder to flag as unusual.

The malware hides inside trusted applications. A technique called DLL sideloading, where a malicious file is disguised as a required component of legitimate software, lets NeedyMantis shelter behind programs such as Poedit, curl, Vim, and TightVNC. Most security tools trust those names. In at least one recorded intrusion, the attackers used a piece of software called Impacket to copy both the legitimate programs and the malicious files across the network before running them.

Its loaders, the small programs that unpack and launch the main code, use custom encrypted archives and rotating encryption keys. That is a deliberate obstacle for researchers trying to analyse what they have found.

Attribute Detail
First observed October 2025
Sectors targeted Telecoms, universities, medical nonprofits, IGOs, govt contractors
Linked group Storm-3069 (China-based, unattributed to state entity)
Initial discovery DAEMON Tools supply chain investigation
Communication method HTTPS and WebSockets
Disguise technique DLL sideloading via legitimate software

Should affected organisations be worried?

Yes, particularly if they hold sensitive communications data. The target list overlaps almost exactly with the organisations Salt Typhoon, a separate China-linked group, swept through in a wave of telecom breaches last year. NeedyMantis is built for the phase that comes after an attacker is already inside, which is precisely the phase many security tools are not tuned to catch.

Threat Vectr's own leak-site tracking does not show NeedyMantis-linked victims listed publicly, which is consistent with espionage rather than ransomware: groups after intelligence tend not to advertise their haul.

Microsoft's advisory recommends running endpoint detection and response software, which monitors devices for suspicious behaviour, in block mode. That setting lets the software automatically stop threats it finds post-breach, even when a conventional antivirus scan has not flagged anything. Watching for unusual file-copying activity, unexpected DLL loading, and anomalous outbound web connections is likely more reliable than waiting for a signature match against the malware's code itself.

If your organisation works in any of the named sectors, this is a good moment to confirm that security software is set to its most active response mode, not just monitoring.

© 2026 Threat Vectr