Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Threat Intel

China-linked NeedyMantis implant hid in telecoms for a year

Microsoft exposed NeedyMantis, an espionage implant used inside telecoms, universities and government contractors, and released detection tools.

By · Published · Updated · 4 min read

China-linked NeedyMantis implant hid in telecoms for a year

A China-linked group spent nearly a year running a spy implant called NeedyMantis inside sensitive networks, Tech Times reports, citing Microsoft.

Who was targeted

  • Telecommunications providers
  • Universities
  • Medical non-profits
  • Intergovernmental organizations
  • Government contractors

What makes NeedyMantis different

NeedyMantis does not break into networks. It is a post-compromise implant, installed after attackers already have access, to stay hidden for the long term. It used DLL sideloading — getting a trusted program to load a malicious file — to avoid detection.

How much data was stolen is still unknown.

What Microsoft released

Microsoft published indicators of compromise, hunting queries for Defender XDR and Microsoft Sentinel, and new antivirus signatures, so organizations can check whether they were affected.

Why it matters

Telecom networks carry calls and messages for millions of people, making them prime espionage targets. Finding an implant like this means the original break-in may have happened even earlier.

Sources

Read next