Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

Executive Summary

Microsoft’s technical analysis revealed that attackers used the NeedyMantis malware family to keep long‑term access in networks they had already breached. The tool has appeared in a handful of targeted attacks against telecom firms, universities, medical nonprofits, intergovernmental bodies, and government contractors, with activity traced back at least to early 2023.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-28T18:35:42+00:00 - Category: threat-intel

Original Description: Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use goes back to at least

"He that never changes his opinions, never corrects his mistakes, and will never be wiser on the morrow than he is today."

— Tryon Edwards
Source: The Hacker News