Threat Intelligence

New 'NeedyMantis' Malware Gives Attackers Long-Term Access to Networks

Dark Reading · 30 Sept 2026
Key Takeaway If your business works with universities, healthcare, telco, or government clients, review your network monitoring and access controls, as these sectors are being actively targeted by sophisticated, persistent threat actors.

Microsoft researchers have uncovered a new malware framework called NeedyMantis being used by a China-based threat actor in targeted attacks. The malware has been observed in intrusions against telecommunications companies, universities, medical organisations, and government-related entities.

Unlike opportunistic cybercrime, this campaign appears focused on gaining long-term, persistent access to compromised networks rather than causing immediate disruption. This type of intrusion is typically associated with espionage-style operations, where attackers quietly maintain a foothold to monitor or extract sensitive information over time.

While Australian small businesses are less likely to be direct targets of state-linked espionage campaigns, organisations that supply services to universities, healthcare providers, telcos, or government bodies should be aware that such attacks can spread through supply chains and partner networks.

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.