Microsoft researchers identified a previously unknown malware framework deployed by a China-based threat actor tracked as NeedyMantis in targeted campaigns against telecommunications providers, educational institutions, healthcare organizations, and government agencies.

The threat actor uses this bespoke malware framework to establish long-term persistence within compromised networks. NeedyMantis operates with operational discipline typical of state-sponsored groups, selecting high-value targets across sectors critical to national infrastructure and intelligence gathering.

Microsoft's analysis reveals the malware framework provides attackers with flexible command-and-control capabilities and data exfiltration functions. The framework's architecture allows operators to maintain access to networks for extended periods, enabling sustained espionage operations. Telcos represent particularly valuable targets, offering access to communications infrastructure and metadata. Universities provide research intelligence and access to government-connected personnel. Healthcare and government sectors grant direct access to sensitive systems handling classified or protected information.

The targeting pattern aligns with known Chinese state-sponsored objectives. Intelligence agencies assess that China prioritizes technical espionage against telecommunications infrastructure to monitor communications traffic, intellectual property theft from research institutions, and direct access to government networks supporting diplomatic and military operations.

NeedyMantis distinguishes itself through custom malware development rather than reliance on publicly available tools. This approach reduces detection risk, as security vendors lack existing signatures and behavioral profiles. Custom frameworks also allow threat actors to tailor functionality to specific network environments and defense mechanisms they encounter.

The malware framework includes components for command execution, file transfer, and process injection. Attackers gain initial access through spear-phishing campaigns and exploitation of unpatched vulnerabilities. Once inside networks, the framework establishes persistence through registry modifications, scheduled tasks, and lateral movement to critical systems.

Microsoft provided indicators of compromise and network signatures enabling organizations to identify NeedyMantis activity in their environments. Organizations should prioritize hunting for this malware across network logs and endpoint telemetry dating back months, as the campaign operated undetected for extended periods before discovery.

Telecommunications providers face urgent risk. NeedyMantis access to telco networks enables monitoring of encrypted communications, collection of call metadata, and potential manipulation of network infrastructure. Regulatory bodies in affected countries should notify impacted carriers and mandate breach notifications to customers potentially affected by communications interception.

Universities should assume research collaboration with government-connected institutions places them at elevated risk. Healthcare organizations handling sensitive patient data and medical research require enhanced endpoint monitoring and network segmentation to limit lateral movement if initial compromises occur.

Government agencies must conduct comprehensive network forensics across all systems that could host the malware framework. Affected departments should implement enhanced credential vetting procedures, as long-term access may have enabled harvesting of authentication materials used for lateral movement.

Organizations lacking Microsoft Defender or equivalent endpoint detection capabilities face elevated risk, as custom malware typically evades legacy antivirus solutions. Deploying behavioral detection systems and network traffic analysis provides alternative detection methods when endpoint visibility remains limited.