NeedyMantis Malware Framework Enables Persistent Network Access
A stealthy malware framework known as NeedyMantis has been enabling attackers to remain hidden inside compromised networks for extended periods, according to Microsoft Threat Intelligence. The company's analysis suggests that NeedyMantis is composed of multiple components written in C++ and x64 shellcode.
The malware operation has been active since at least October 2025 and has targeted telecommunications providers, universities, and government-linked organizations. Microsoft attributed the activity as emerging from China, but did not attribute it to a state-sponsored threat actor.
NeedyMantis is deployed after initial access has been gained by the threat actor, and is used to maintain long-term access and support follow-on operations. The attackers disguise their malicious activity by packaging it alongside downloads of open-source software.
To defend networks against NeedyMantis, Microsoft recommends turning on cloud-delivered protection and block at first sight, running Endpoint Detection and Response in block mode, enabling network protection, and configuring automatic attack disruption.