Microsoft reports that a China-based threat actor uses a malware framework dubbed “NeedyMantis” to maintain long-term access to networks it has already breached. The activity is described as targeted intrusions rather than broad, automated attacks.
According to Microsoft’s technical analysis as summarized by multiple outlets, NeedyMantis has been observed in a limited number of incidents. Affected organizations include telecommunications providers, universities, medical-related organizations and nonprofits, intergovernmental bodies, and government contractors. The reporting also indicates the activity dates back at least to a prior point, though the outlets provide only partial details in the excerpts.
Both sources focus on the same central point: NeedyMantis is used as a persistence mechanism after initial compromise. The coverage differs mainly in emphasis—one outlet frames the development as “long-term access to compromised networks,” while another highlights the malware family’s role in sustaining access within already breached environments—but neither contradicts the core attribution and usage described by Microsoft.