NeedyMantis: China-Linked Malware Used in Targeted Operations
Microsoft Threat Intelligence has identified NeedyMantis, a modular post-compromise malware family used in targeted operations against organizations worldwide. The malware's activity dates back to at least October 2025 and is associated with threat actors operating from China.
NeedyMantis is typically deployed after a threat actor has established access to a target environment, indicating its use for maintaining long-term access and supporting follow-on operations. Its architecture combines multiple loaders, custom encrypted file archives, and modular components that enable operators to evade analysis and extend functionality.
The malware's packaging and distribution involve masquerading as legitimate software, with the first-stage loader being loaded through DLL sideloading. NeedyMantis has been observed in intrusions affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors.