Skip to content

Security1 publisher2 min readPublished

Microsoft says China-linked operators hand-install NeedyMantis to keep hold of breached networks

Microsoft says China-linked operators have used NeedyMantis since at least October 2025 to keep access to telecom, university and government-linked networks. It goes in after the break-in, so defenders have to hunt for it inside networks already breached.

The Watch · Security desk

Illustration accompanying Microsoft says China-linked operators hand-install NeedyMantis to keep hold of breached networks

What happened

  • Operators install NeedyMantis by hand, over remote access, on machines they have already compromised.
  • The first-stage loader comes packaged with legitimate open-source programs, including Poedit, curl, Vim and TightVNC, and loads through DLL side-loading.
  • A second-stage loader embeds the implant further, and the final stage contacts a command server that lets the operator keep access, exfiltrate data and add components.
  • Microsoft ties at least one operator to Storm-3069, a group linked to the Daemon Tools supply chain compromise, but found no evidence NeedyMantis was distributed that way.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Detection tuned to the initial break-in does not cover an implant installed afterwards, so teams have to hunt for side-loading on hosts they may already consider handled.
  • exposure Telecoms, universities and government-linked bodies that cleaned up an earlier intrusion may still host a working NeedyMantis channel back to the operator.
  • decision Teams running endpoint products other than Defender cannot apply most of Microsoft's guidance as written and have to map it onto their own controls for side-loading and unknown binaries.

Some of the side-loaded DLLs pose as Microsoft Office, Broadcom, Intel and NVIDIA components [11]. The implant is built from C++ modules and x64 shellcode [8]. It also carries anti-analysis code meant to hinder detection by security software and review by human analysts [13].

The order of events decides where a responder can catch this. Microsoft saw NeedyMantis only in environments the operators already held. It assesses that the framework exists to keep that access and support later operations [6]. How the operators get in is still unknown [7]. A hunt can find the install itself: a legitimate open-source program loading a DLL that claims to be an Office, Intel or NVIDIA part [9][11].

Microsoft places the activity in China but has not attributed it to an actor working for the Chinese state [4]. It has not ruled out the supply chain as a way in. "Supply chain activity remains one possible means by which an actor could gain the access necessary to deploy the malware," Microsoft wrote [16].

The dates show a sustained operation. The tooling has been in use since at least October 2025, and Microsoft published its analysis on September 28 [2][1]. Microsoft could not determine whether one operator runs all of it. Storm-3069 is the one operator it names [5].

Microsoft's recommended mitigations are product settings. Three of the four name Microsoft Defender features: EDR in block mode, network protection in Defender for Endpoint and automatic attack disruption in Defender XDR [1][17]. The fourth is cloud-delivered protection with block at first sight, aimed at new and unknown variants [17].

What to watch

  • Any finding from Microsoft or other researchers on how NeedyMantis operators gain initial access.
  • Attribution of NeedyMantis intrusions to operators other than Storm-3069, which would show whether the framework is shared.
  • Indicators of compromise published in a form defenders can use outside the Microsoft Defender stack.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories