Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

NeedyMantis Malware Enables Long‑Term Persistence in Breached Telecom, University, and Government Networks

Microsoft reports that the NeedyMantis backdoor is used to maintain footholds in networks across telecom, academia, and government sectors. The persistence highlights the importance of continuous privileged‑access monitoring for audit readiness.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
5 sector(s)
✅
Actions
3 recommended
📰
Source
thehackernews.com

NeedyMantis Malware Enables Long‑Term Persistence in Breached Telecom, University, and Government Networks

What Happened — Microsoft’s threat‑research team identified the NeedyMantis malware family being used to retain footholds after an initial breach. The tool has surfaced in a handful of targeted intrusions across telecommunications operators, universities, medical non‑profits, intergovernmental bodies, and government contractors, with activity dating back several years.

Why It Matters for Trust & Control Assurance

  • Persistent malware like NeedyMantis demonstrates a failure to detect and terminate unauthorized privileged sessions – a core control‑area that continuous‑monitoring programs are built to protect.
  • Evidence of long‑term access highlights the need for robust identity‑and‑access‑management (IAM) policies, real‑time session analytics, and defensible audit logs that can be presented during compliance reviews.
  • Mapping this incident to a single control objective (continuous monitoring of privileged access) satisfies requirements across multiple frameworks (e.g., NIST CSF 2.0, ISO 27001, SOC 2).

Who Is Affected – Telecommunications providers, higher‑education institutions, health‑sector non‑profits, intergovernmental organizations, and government‑contracting firms.

Recommended Actions – Review and tighten privileged‑access controls, implement continuous session monitoring, and collect immutable logs to prove detection and response capabilities. Source: The Hacker News

Technical Notes – NeedyMantis is a custom backdoor that establishes encrypted C2 channels, creates scheduled tasks for persistence, and can download additional payloads. No public CVE is associated; the threat is delivered via compromised credentials or previously exploited vulnerabilities. Source: Microsoft Technical Analysis

📰 Original Source
https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →