Microsoft has attributed targeted intrusions to a China-based actor using a previously unidentified malicious software framework now being referred to as NeedyMantis. The reported victim set is high value and operationally sensitive: telecommunications providers, universities, medical organizations, and government-related entities. The important defensive point is not the name. It is the mission profile: long-term access inside networks where identity, research data, patient care systems, lawful intercept-adjacent infrastructure, and citizen services create outsized leverage for espionage and pre-positioning.
Public reporting has not, as of this writing, provided a CVE, a complete IOC set, a final payload hash list, or a vendor patch. Do not wait for those artifacts. Novel frameworks are specifically built to defeat hash-based and signature-driven controls. The correct posture is assumed breach: hunt for persistence, abnormal identity use, proxy execution, rare egress, and cross-environment movement between IT, research, clinical, and telecom operational systems.
What Is at Risk
The sectors named in the reporting are attractive for different but overlapping reasons. Telcos expose subscriber metadata, routing control, peering relationships, and sometimes pathways into managed customer environments. Universities hold pre-publication research, export-controlled work, and large populations of weakly governed endpoints. Medical organizations combine identity data, operational uptime pressure, and third-party biomedical connectivity. Government-related organizations provide policy insight, credentials, and trust relationships that can be reused in downstream supply-chain or inter-agency compromise.
For defenders, the risk window is measured in months, not days. A long-term access framework usually survives by blending into legitimate administration: scheduled tasks, services, WMI subscriptions, startup mechanisms, remote management tooling, compromised service accounts, and low-and-slow command and control. If your detection strategy depends on known bad hashes, you are likely blind during the most valuable phase of the intrusion.
Technical Analysis
Affected products, versions, and platforms: no specific vulnerable product or version has been disclosed in the source item. The campaign should be treated as platform-agnostic across Windows endpoints and servers, Linux infrastructure, network edge devices, virtualization management planes, identity providers, and SaaS-connected mail or collaboration tenants. Telecom and university environments should assume Linux, network appliances, and identity systems are in scope alongside Windows.
CVE identifiers and CVSS: none are identified in the source reporting. No CVE should be inferred. There is also no basis to claim CISA KEV inclusion for a specific vulnerability from this item alone.
How the attack works from a defender's perspective: the reporting indicates targeted intrusions using a previously unidentified framework for durable access. In practical terms, prioritize the following chain: initial access through spear phishing, exposed remote services, edge device weakness, stolen credentials, or third-party trust; execution through script interpreters, signed binary proxy execution, or malicious loaders; persistence through scheduled tasks, services, WMI event subscriptions, startup items, account creation, SSH keys, token theft, or identity federation abuse; command and control through rare outbound destinations, DNS tunneling, cloud service abuse, or compromised infrastructure; collection and staging from file shares, mailboxes, research repositories, clinical data stores, network configuration backups, and authentication databases.
Exploitation status: confirmed targeted activity is reported by Microsoft. Because the framework is described as previously unidentified, defenders should assume limited antivirus coverage, limited public telemetry, and active use against organizations matching the victim profile. The absence of public IOCs is not evidence of absence in your environment.
Detection and Response
Use behavior-first analytics. Scope hunts to at least 30 days where telemetry retention allows, and extend to 90 days for identity, VPN, edge, and authentication logs because long-term actors often return infrequently. Prioritize assets by mission impact: identity providers, PKI, email gateways, VPN and ZTNA brokers, firewall and SD-WAN controllers, VMware or Hyper-V management, backup infrastructure, telecom OSS/BSS, research storage, EHR-adjacent systems, and privileged workstations.
---
title: Persistence Via Scheduled Task From User Writable Paths
id: 7d4a9c21-5f6b-4e0c-9a31-2b8d6f1a0c44
status: experimental
description: Detects creation of scheduled tasks running with elevated context from user writable or staging paths, consistent with long-term access tradecraft.
references:
- https://attack.mitre.org/techniques/T1053/005/
- https://www.darkreading.com/threat-intelligence/needymantis-long-term-access-compromised-networks
author: Security Arsenal
date: 2026/04/25
tags:
- attack.persistence
- attack.t1053.005
logsource:
category: process_creation
product: windows
detection:
selection_tool:
CommandLine|contains:
- 'schtasks'
- '/create'
selection_priv:
CommandLine|contains:
- '/ru system'
- '/rl highest'
- '/ru administrator'
selection_path:
CommandLine|contains:
- 'AppData'
- 'Temp'
- 'Public'
- 'ProgramData'
- 'Users'
condition: all of selection_*
falsepositives:
- Software deployment and endpoint management tools creating elevated tasks
- Rare developer bootstrap scripts in labs
level: high
---
title: WMI Event Subscription Persistence Creation
id: 1c8f6b44-92de-4ac7-bf53-7e2a0d9c6b18
status: experimental
description: Detects creation of WMI event filters, consumers, or compiled MOF artifacts commonly used for durable fileless persistence.
references:
- https://attack.mitre.org/techniques/T1546/003/
- https://www.darkreading.com/threat-intelligence/needymantis-long-term-access-compromised-networks
author: Security Arsenal
date: 2026/04/25
tags:
- attack.persistence
- attack.t1546.003
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|contains:
- 'powershell'
- 'pwsh'
- 'wmic'
- 'mofcomp'
selection_cmd:
CommandLine|contains:
- 'Register-WmiEvent'
- '__EventFilter'
- '__EventConsumer'
- 'CommandLineEventConsumer'
- 'ActiveScriptEventConsumer'
- 'mofcomp'
- 'root/subscription'
condition: selection_img and selection_cmd
falsepositives:
- Enterprise monitoring agents and validated management frameworks
level: critical
---
title: Signed Binary Proxy Execution From Staging Directories
id: 9b31d7e5-6c20-4f8a-a07d-4e5c8b2f9a60
status: experimental
description: Detects rundll32 or regsvr32 style proxy execution referencing user writable paths, scripts, or remote payloads.
references:
- https://attack.mitre.org/techniques/T1218/
- https://www.darkreading.com/threat-intelligence/needymantis-long-term-access-compromised-networks
author: Security Arsenal
date: 2026/04/25
tags:
- attack.defense_evasion
- attack.t1218
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|contains:
- 'rundll32'
- 'regsvr32'
selection_cmd:
CommandLine|contains:
- 'AppData'
- 'Temp'
- 'Public'
- 'ProgramData'
- 'http:'
- 'https:'
- 'scrobj'
- 'shell32,control_rundll'
- '/i:'
condition: selection_img and selection_cmd
falsepositives:
- Rare installers and line-of-business deployment scripts
level: high
// Hunt persistence and proxy execution from writable paths in Microsoft Defender XDR or Sentinel advanced hunting
let lookback = 30d;
let suspicious_terms = dynamic(['schtasks','/create','Register-WmiEvent','__EventFilter','__EventConsumer','CommandLineEventConsumer','ActiveScriptEventConsumer','mofcomp','rundll32','regsvr32','scrobj','/i:http']);
let writable_paths = dynamic(['AppData','Temp','Public','ProgramData','Users']);
DeviceProcessEvents
| where TimeGenerated > ago(lookback)
| where ProcessCommandLine has_any (suspicious_terms) and (FolderPath has_any (writable_paths) or ProcessCommandLine has_any (writable_paths))
| summarize Executions=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Users=dcount(AccountName), Hosts=dcount(DeviceName), SampleCommand=any(ProcessCommandLine) by DeviceName, AccountName, FileName, FolderPath, SHA256
| sort by LastSeen desc;
// Correlate processes launched from writable paths with outbound network activity
DeviceNetworkEvents
| where TimeGenerated > ago(lookback)
| where InitiatingProcessFolderPath has_any (writable_paths) or InitiatingProcessCommandLine has_any (writable_paths)
| summarize Connections=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Destinations=dcount(RemoteIP), Ports=make_set(RemotePort), TotalBytesSent=sumif(SentBytes, SentBytes > 0) by DeviceName, InitiatingProcessAccountName, InitiatingProcessFileName, InitiatingProcessFolderPath, RemoteUrl
| where Destinations > 3 or Connections > 50
| sort by LastSeen desc;
// Linux and syslog-visible persistence or account manipulation ingested into Sentinel
Syslog
| where TimeGenerated > ago(lookback)
| where SyslogMessage has_any ('useradd','usermod','passwd','crontab','systemctl enable','authorized_keys','ssh-rsa','chmod 4755','/etc/sudoers')
| summarize Events=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated) by HostName, ProcessName, SyslogMessage
| sort by LastSeen desc;
// Edge and firewall telemetry for rare long-lived egress, adjust facility names to your environment
CommonSecurityLog
| where TimeGenerated > ago(lookback)
| where DeviceVendor has_any ('Palo Alto','Fortinet','Check Point','Cisco','Juniper') or isnotempty(DeviceVendor)
| summarize Flows=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), BytesOut=sum(SentBytes), SrcHosts=dcount(SourceIP) by DestinationIP, DestinationPort, ApplicationProtocol, DeviceAction
| where Flows > 100 and DestinationPort in (443, 80, 853, 53)
| sort by Flows desc
-- Hunt endpoint processes and persistence-adjacent artifacts without relying on hashes
SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE Exe =~ 'AppData|Temp|Public|ProgramData'
OR CommandLine =~ 'schtasks|Register-WmiEvent|__EventFilter|CommandLineEventConsumer|ActiveScriptEventConsumer|mofcomp|regsvr32|rundll32|scrobj'
SELECT FullPath, Size, Mtime, Atime, Ctime
FROM glob(globs=['C:/Users/*/AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup/*','C:/ProgramData/Microsoft/Windows/Start Menu/Programs/Startup/*'])
ORDER BY Mtime DESC
LIMIT 200
#Requires -RunAsAdministrator
[CmdletBinding(SupportsShouldProcess=$true)]
param(
[string]$ExportRoot = 'C:/IR/NeedyMantis-Triage',
[switch]$ApproveRemediation,
[string[]]$AllowTaskName = @(),
[string[]]$AllowServiceName = @(),
[string[]]$AllowProcessPath = @()
)
$ErrorActionPreference = 'Continue'
New-Item -ItemType Directory -Force -Path $ExportRoot | Out-Null
$stamp = Get-Date -Format 'yyyyMMdd-HHmmss'
$report = Join-Path $ExportRoot ('needymantis-audit-' + $stamp + '.csv')
$findings = New-Object System.Collections.Generic.List[object]
function Add-Finding {
param([string]$Type,[string]$Name,[string]$Path,[string]$Reason,[string]$Action)
$findings.Add([pscustomobject]@{ Type=$Type; Name=$Name; Path=$Path; Reason=$Reason; Action=$Action; Host=$env:COMPUTERNAME; Time=(Get-Date) })
}
$writable = 'AppData|Temp|Public|ProgramData|Users'
$isAllowed = {
param($name,$path,$allowNames,$allowPaths)
($allowNames -contains $name) -or ($allowPaths | Where-Object { $path -like ('*' + $_ + '*') })
}
# Scheduled tasks with actions in writable or staging paths
Get-ScheduledTask | ForEach-Object {
$task = $_
foreach ($action in $task.Actions) {
$exe = [string]$action.Execute
$args = [string]$action.Arguments
$joined = ($exe + ' ' + $args)
if ($joined -match $writable -and -not (& $isAllowed $task.TaskName $joined $AllowTaskName $AllowProcessPath)) {
$actionTaken = 'Review only'
if ($ApproveRemediation -and $PSCmdlet.ShouldProcess($task.TaskName,'Disable scheduled task')) {
Disable-ScheduledTask -TaskName $task.TaskName -TaskPath $task.TaskPath -ErrorAction SilentlyContinue
$actionTaken = 'Disabled pending IR validation'
}
Add-Finding -Type 'ScheduledTask' -Name ($task.TaskPath + $task.TaskName) -Path $joined -Reason 'Task action references writable or staging path' -Action $actionTaken
}
}
}
# Services with binaries in writable paths
Get-CimInstance Win32_Service | ForEach-Object {
$svc = $_
$path = [string]$svc.PathName
if ($path -match $writable -and -not (& $isAllowed $svc.Name $path $AllowServiceName $AllowProcessPath)) {
$actionTaken = 'Review only'
if ($ApproveRemediation -and $PSCmdlet.ShouldProcess($svc.Name,'Stop and disable service')) {
Stop-Service -Name $svc.Name -Force -ErrorAction SilentlyContinue
Set-Service -Name $svc.Name -StartupType Disabled -ErrorAction SilentlyContinue
$actionTaken = 'Stopped and disabled pending IR validation'
}
Add-Finding -Type 'Service' -Name $svc.Name -Path $path -Reason 'Service binary path references writable or staging path' -Action $actionTaken
}
}
# Startup entries surfaced through CIM without registry path dependence
Get-CimInstance Win32_StartupCommand | ForEach-Object {
$item = $_
$cmd = [string]$item.Command
if ($cmd -match $writable -and -not (& $isAllowed $item.Name $cmd @() $AllowProcessPath)) {
Add-Finding -Type 'StartupCommand' -Name $item.Name -Path $cmd -Reason 'Startup command references writable or staging path' -Action 'Review only; remove through approved change control'
}
}
# WMI permanent event subscriptions in common persistence namespaces
foreach ($ns in @('root/subscription','root/default')) {
Get-CimInstance -Namespace $ns -ClassName __EventFilter -ErrorAction SilentlyContinue | ForEach-Object {
Add-Finding -Type 'WMIEventFilter' -Name $_.Name -Path ($ns + ' query: ' + [string]$_.Query) -Reason 'Permanent WMI event filter present' -Action 'Review only; remove only with IR lead approval'
}
Get-CimInstance -Namespace $ns -ClassName CommandLineEventConsumer -ErrorAction SilentlyContinue | ForEach-Object {
Add-Finding -Type 'WMICommandConsumer' -Name $_.Name -Path ([string]$_.CommandLineTemplate + ' ' + [string]$_.ExecutablePath) -Reason 'CommandLineEventConsumer present' -Action 'Review only; remove only with IR lead approval'
}
Get-CimInstance -Namespace $ns -ClassName ActiveScriptEventConsumer -ErrorAction SilentlyContinue | ForEach-Object {
Add-Finding -Type 'WMIScriptConsumer' -Name $_.Name -Path ([string]$_.ScriptText) -Reason 'ActiveScriptEventConsumer present' -Action 'Review only; remove only with IR lead approval'
}
}
# Local admin drift and recently created local accounts
Get-LocalGroupMember -Group 'Administrators' -ErrorAction SilentlyContinue | ForEach-Object {
Add-Finding -Type 'LocalAdmin' -Name $_.Name -Path $_.ObjectClass -Reason 'Validate every local administrator against change records' -Action 'Review only'
}
Get-LocalUser | Where-Object { $_.Enabled -eq $true } | ForEach-Object {
if ($_.WhenCreated -gt (Get-Date).AddDays(-45)) {
Add-Finding -Type 'RecentLocalUser' -Name $_.Name -Path ('Created ' + $_.WhenCreated) -Reason 'Recently created enabled local user inside hunt window' -Action 'Review only'
}
}
$findings | Sort-Object Type, Name | Export-Csv -NoTypeInformation -Path $report
$findings | Sort-Object Type, Name | Format-Table -AutoSize
Write-Output ('Report written to ' + $report)
Write-Output 'Default mode is audit only. Re-run with -ApproveRemediation only after snapshot, isolate approval, and allowlists are reviewed.'
Response Priorities for the First 24 Hours
Establish incident command and preserve evidence before broad remediation. Snapshot or image affected servers and management appliances. Export authentication, VPN, edge, EDR, DNS, proxy, cloud audit, and identity logs before retention rolls over. Reset credentials only in a coordinated sequence: start with tier-zero accounts, service accounts with interactive rights, VPN and remote access accounts, email administrators, backup administrators, hypervisor administrators, telecom OSS/BSS privileged users, and any account showing impossible travel, token reuse, or MFA fatigue.
Contain by identity and egress, not just by host. Disable suspicious persistence only after capture unless host risk demands immediate isolation. Enforce MFA phishing resistance for remote and privileged access, review conditional access and token lifetime, rotate exposed secrets, and validate federation signing certificates. Restrict outbound traffic by default for servers, management interfaces, biomedical devices where feasible, and telecom control systems; alert on new destinations rather than known bad lists. Segment research, clinical, guest, student, and operations networks from tier-zero assets. Validate backups are immutable, offline copies exist, and restore paths are tested.
Remediation and Hardening
There is no vendor patch or fixed version to cite because this news item describes a campaign and framework rather than a disclosed product vulnerability. Track Microsoft Threat Intelligence and CISA channels for follow-on IOCs or KEV additions, but operate now on behavior. Official starting points: https://www.microsoft.com/en-us/security/blog/ and https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Remove persistence only after forensic capture; premature deletion can destroy the only evidence of scope. Reimage systems with suspected kernel, hypervisor, firmware, or identity-plane compromise. Do not trust a clean antivirus result from a host that had confirmed access. Rotate credentials that touched the host, including cached secrets and service principals. Review SSH authorized keys, sudoers, cron, systemd units, container orchestration service accounts, network device local users, TACACS or RADIUS fallback, SNMP communities, and saved configuration backups.
Reduce future dwell time with measurable controls: deploy EDR to servers and management workstations, not just endpoints; enable command-line, process ancestry, AMSI, script block, WMI, and PowerShell logging; centralize edge and identity logs; alert on new admin group members, new service principals, new federation trusts, new inbox rules, OAuth grants, and MFA method changes; require FIDO2 or equivalent for privileged access; enforce just-in-time administration; block server-to-internet egress except through approved proxies; baseline rare parent-child process relationships; and run quarterly assumed-breach hunts against persistence and egress rather than annual compromise assessments.
For telcos, add control-plane and management-plane validation: secure BGP and peering change workflows, monitor configuration diffs, restrict NETCONF or SSH to jump hosts, review lawful intercept and mediation system access, and watch for bulk export of subscriber or routing metadata. For healthcare, coordinate containment with clinical safety so EHR, imaging, pharmacy, and biomedical dependencies are not disrupted without a downtime procedure. For universities, prioritize identity hygiene for students and staff, research storage access review, and segmentation between high-performance computing, grant administration, and general campus networks.
If you confirm NeedyMantis activity, escalate to a full IR retainer-grade workflow: scoped timeline, crown-jewel data access review, credential exposure matrix, third-party notification obligations, regulator assessment for HIPAA or state breach laws where applicable, law enforcement engagement where appropriate, and a lessons-learned plan tied to funded control gaps.
Related Resources
Security Arsenal Incident Response Services AlertMonitor Platform Book a SOC Assessment incident-response Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.