Security1 publisher2 min readPublished
Microsoft says China-linked operators hand-install NeedyMantis to keep hold of breached networks
Microsoft says China-linked operators have used NeedyMantis since at least October 2025 to keep access to telecom, university and government-linked networks. It goes in after the break-in, so defenders have to hunt for it inside networks already breached.
The Watch · Security desk

What happened
- Operators install NeedyMantis by hand, over remote access, on machines they have already compromised.
- The first-stage loader comes packaged with legitimate open-source programs, including Poedit, curl, Vim and TightVNC, and loads through DLL side-loading.
- A second-stage loader embeds the implant further, and the final stage contacts a command server that lets the operator keep access, exfiltrate data and add components.
- Microsoft ties at least one operator to Storm-3069, a group linked to the Daemon Tools supply chain compromise, but found no evidence NeedyMantis was distributed that way.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Detection tuned to the initial break-in does not cover an implant installed afterwards, so teams have to hunt for side-loading on hosts they may already consider handled.
- exposure Telecoms, universities and government-linked bodies that cleaned up an earlier intrusion may still host a working NeedyMantis channel back to the operator.
- decision Teams running endpoint products other than Defender cannot apply most of Microsoft's guidance as written and have to map it onto their own controls for side-loading and unknown binaries.
Some of the side-loaded DLLs pose as Microsoft Office, Broadcom, Intel and NVIDIA components [11]. The implant is built from C++ modules and x64 shellcode [8]. It also carries anti-analysis code meant to hinder detection by security software and review by human analysts [13].
The order of events decides where a responder can catch this. Microsoft saw NeedyMantis only in environments the operators already held. It assesses that the framework exists to keep that access and support later operations [6]. How the operators get in is still unknown [7]. A hunt can find the install itself: a legitimate open-source program loading a DLL that claims to be an Office, Intel or NVIDIA part [9][11].
Microsoft places the activity in China but has not attributed it to an actor working for the Chinese state [4]. It has not ruled out the supply chain as a way in. "Supply chain activity remains one possible means by which an actor could gain the access necessary to deploy the malware," Microsoft wrote [16].
The dates show a sustained operation. The tooling has been in use since at least October 2025, and Microsoft published its analysis on September 28 [2][1]. Microsoft could not determine whether one operator runs all of it. Storm-3069 is the one operator it names [5].
Microsoft's recommended mitigations are product settings. Three of the four name Microsoft Defender features: EDR in block mode, network protection in Defender for Endpoint and automatic attack disruption in Defender XDR [1][17]. The fourth is cloud-delivered protection with block at first sight, aimed at new and unknown variants [17].
What to watch
- Any finding from Microsoft or other researchers on how NeedyMantis operators gain initial access.
- Attribution of NeedyMantis intrusions to operators other than Storm-3069, which would show whether the framework is shared.
- Indicators of compromise published in a form defenders can use outside the Microsoft Defender stack.