NeedyMantis Malware Used for Long-Term Persistence in Targeted Intrusions
Microsoft analysis reveals backdoor malware targeting telecommunications, academia, and government sectors

Key Takeaways
- Microsoft has identified NeedyMantis malware used for long-term persistence in breached networks.
- Targeted sectors include telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors.
- Activity has been tracked since at least 2023 and remains ongoing as of September 2026.
- The malware is attributed to threat actors consistent with nation-state activity based on targeting profiles.
- No specific CVEs or exploitation vectors are detailed; mitigation focuses on malware removal, credential rotation, and network segmentation.
Quick answers
- What happened?
- Microsoft has identified a malware family named NeedyMantis being used by threat actors to maintain long-term, unauthorized access to already-breached networks. The malware has been observed in targeted intrusions across a range of sectors, including telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors. Activity has been tracked since at least 2023 and remains ongoing.
- What should defenders do?
- Microsoft recommends standard incident response actions: removal of identified malware, credential rotation, and network segmentation to disrupt persistence and limit lateral movement.
According to Microsoft's technical analysis, the NeedyMantis malware family has been deployed in a small number of targeted operations aimed at maintaining persistence within compromised environments. The victims span multiple high-value sectors, indicating a strategic focus on entities with access to sensitive data or critical infrastructure. While the specific initial access vectors used to deploy NeedyMantis are not detailed in the reporting, the malware's primary function is to establish and maintain backdoor access, allowing threat actors to retain control over networks they have already breached. The reporting notes that the use of NeedyMantis goes back to at least 2023, with activity identified as recently as September 2026. Microsoft has attributed the activity to threat actors consistent with nation-state operations based on the targeting profile, though specific threat actor attribution and detailed tactics, techniques, and procedures (TTPs) remain under investigation. No specific software vulnerabilities or CVE identifiers have been associated with the NeedyMantis deployment in the available summary. The impact of the malware centers on unauthorized persistent access, which could facilitate subsequent data exfiltration, lateral movement within the network, or disruption of critical services. Mitigation guidance from Microsoft focuses on standard incident response procedures, including the removal of identified malware, credential rotation, and network segmentation to limit further unauthorized access.
Security Details
NeedyMantis is a malware family used for maintaining long-term, unauthorized access (backdoor) to already-breached networks. It has been observed in targeted intrusions across telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors since at least 2023. Specific exploitation vectors and CVE associations are not detailed in the reporting.
Mitigation
Microsoft recommends standard incident response actions: removal of identified malware, credential rotation, and network segmentation to disrupt persistence and limit lateral movement.
Sources
The Hacker News
Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
Sep 28, 2026 · 18:35
Original link
Related Security News

Star Blizzard Campaign Targets 100+ Organizations with Fake Event Invitations
Microsoft reports that the Russian state-sponsored threat actor Star Blizzard has been conducting a sustained campaign since January 2026, using fake event invitations to trick targets into installing a backdoor on Windows computers. The operation has affected more than 100 organizations, primarily in the U.S. and U.K., with victims tied to Ukraine. At least one infection has been confirmed, though the full extent of breaches and data exfiltration remains unverified.




