Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

China‑Based Actor Deploys “NeedyMantis” Malware for Persistent Access Across Telcos, Universities, and Healthcare Networks

Microsoft reported a China‑origin threat group using a previously unknown malware framework, ‘NeedyMantis’, to establish long‑term footholds in telecom, academic, medical, and government‑related networks. The campaign underscores the need for continuous monitoring and auditable evidence of detection controls for compliance readiness.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 darkreading.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
4 sector(s)
✅
Actions
3 recommended
📰
Source
darkreading.com

China‑Based Actor Deploys “NeedyMantis” Malware for Persistent Access Across Telcos, Universities, and Healthcare Networks

What Happened — Microsoft observed a China‑origin threat group using a previously unidentified malware framework, dubbed NeedyMantis, to establish long‑term footholds in targeted networks. The campaign spans telecommunications carriers, university research environments, medical institutions, and government‑related entities.

Why It Matters for Trust & Control Assurance

  • Persistent, custom malware underscores the need for continuous monitoring of privileged activity and rapid detection of anomalous behavior.
  • Demonstrates the value of auditable evidence that detection controls are operating as intended across multiple frameworks.
  • Aligns with Verisq’s Control Mapping capability, which helps organizations map detection controls to a unified control spine and collect defensible proof for audit readiness.

Who Is Affected — Telecommunications, higher‑education, healthcare, and government‑related organizations.

Recommended Actions

  • Review and augment detection rules for unknown or custom malware behaviors.
  • Verify that privileged‑account logging is comprehensive, retained, and regularly reviewed.
  • Map your detection and monitoring controls to the VCF objective “Monitor and detect unauthorized access” and gather evidence for compliance audits.

Source: Dark Reading

Technical Notes — The threat leverages a novel malware framework with unknown persistence mechanisms; no public CVE is associated. Attack vector is a custom malware payload delivered via spear‑phishing or compromised supply‑chain components. Targeted data includes network credentials, configuration files, and potentially patient or research data. Source: Dark Reading

📰 Original Source
https://www.darkreading.com/threat-intelligence/needymantis-long-term-access-compromised-networks ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →