Microsoft's threat intelligence team has published a technical analysis of NeedyMantis, a malicious software family deployed by attackers to maintain long-term, persistent access inside networks they had already compromised. According to Microsoft, NeedyMantis has appeared in a small number of highly targeted intrusions hitting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors — and its use stretches back well before its public disclosure.
This is the profile of a classic espionage-grade persistence implant, not commodity malware. NeedyMantis is not how attackers get in — it is how they stay in. That distinction matters enormously for defenders: if you find NeedyMantis on a host, you are not dealing with a single infection event. You are dealing with an established intrusion, an unknown initial access vector, potentially multiple additional persistence mechanisms, and an adversary who has had time to map your environment, stage collection, and position for lateral movement.
If you operate in any of the targeted verticals — telecom, higher education, healthcare nonprofits, intergovernmental bodies, or the defense/government contracting space — you should treat this disclosure as an active hunting trigger, not a news item.
Technical Analysis
What NeedyMantis Is
Per Microsoft's technical analysis, NeedyMantis is a post-compromise implant whose primary function is durable access. Key characteristics of this threat class as described in the reporting:
- Deployment model: Installed after initial breach, indicating a hands-on-keyboard or staged intrusion operation. The initial access vector is separate and may still be unknown in victim environments.
- Targeting: Deliberate, low-volume, victim-selected. Telecommunications providers, universities, medical nonprofits, intergovernmental organizations, and government contractors — a victimology pattern strongly consistent with intelligence collection rather than financially motivated crime.
- Dwell time: Use of the family goes back well before disclosure, meaning the operators prioritized stealth over speed. Long dwell time correlates with deep network mapping, credential theft, and redundant persistence.
- Victim count: "A small number of targeted intrusions" — surgical deployment, not spray-and-pray. This means traditional signature-based AV coverage is likely to lag; behavioral detection and hypothesis-driven hunting are the primary defensive tools.
Why Persistence Implants Are Dangerous
A dedicated persistence family tells you several things about the adversary:
- They expect to lose other access. Implant families like this are typically deployed alongside — or after — web shells, stolen credentials, and legitimate remote access tooling, so that evicting one mechanism does not evict the actor.
- They intend to return. Long-term access is an investment. The operators anticipate months-to-years of presence and have built survivability into their tooling.
- They are collection-oriented. Telecom metadata, university research, medical nonprofit data, and government contractor environments are strategic intelligence targets. Expect data staging, mailbox access, and internal reconnaissance.
Attack Chain Context
Because NeedyMantis is a post-compromise tool, the realistic attack chain in a victim environment looks like:
- Initial access — typically via edge device exploitation, valid credential abuse, or spear phishing (not attributed to NeedyMantis itself).
- Establish foothold — deploy NeedyMantis as a durable implant, commonly under a benign-looking service, scheduled task, or binary name.
- Command and control — low-and-slow beaconing over common web protocols (HTTPS) to blend with legitimate traffic, often to attacker-controlled infrastructure with plausible-looking domains.
- Discovery and credential access — internal reconnaissance, LSASS access, token theft.
- Lateral movement and redundant persistence — additional implants or legitimate-tool abuse on adjacent systems.
- Collection and exfiltration — staged archives exfiltrated over C2 or cloud storage.
No CVE is associated with this disclosure. NeedyMantis is a malware family, not a vulnerability — there is nothing to patch against. Your defensive levers are detection, hunting, and eradication.
Exploitation Status
- Confirmed active in the wild in targeted intrusions.
- Attribution: Tracked by Microsoft; targeted, state-aligned intrusion activity profile.
- CISA KEV: Not applicable (malware family, not a CVE).
- Urgency: High for organizations in targeted verticals. Moderate for all others — hunt anyway, because low-volume implant families frequently expand victimology after disclosure as actors burn tooling.
Detection & Response
The detections below target the behaviors a persistence implant like NeedyMantis must exhibit: durable execution mechanisms (services, scheduled tasks, Run keys), binaries executing from non-standard paths, and low-frequency outbound beaconing from hosts with no business reason for it. Tune thresholds to your baseline.
Sigma Rules
---
title: Suspicious Windows Service Persistence — Non-Standard Binary Path
id: 8f2e4a71-3b6c-4d9e-b1a7-9c4f2e8d5a31
status: experimental
description: Detects creation of Windows services whose binary path resides in user-writable or non-standard directories, a common persistence technique for implants such as NeedyMantis that masquerade as legitimate services.
references:
- https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html
- https://attack.mitre.org/techniques/T1543/003/
author: Security Arsenal
date: 2026/09/15
tags:
- attack.persistence
- attack.privilege_escalation
- attack.t1543.003
logsource:
category: process_creation
product: windows
detection:
selection_tool:
Image|endswith:
- '\sc.exe'
- '\powershell.exe'
- '\pwsh.exe'
CommandLine|contains:
- 'create'
- 'binpath'
selection_path:
CommandLine|contains:
- 'C:\\Users\\'
- 'C:\\ProgramData\\'
- 'C:\\Windows\\Temp\\'
- 'C:\\Temp\\'
- 'AppData\\'
filter_common:
CommandLine|contains:
- 'C:\\ProgramData\\Microsoft\\'
- 'C:\\ProgramData\\Package Cache\\'
condition: selection_tool and selection_path and not filter_common
falsepositives:
- Legitimate software installers registering services from ProgramData
- IT deployment tooling
level: high
---
title: Scheduled Task Created Masquerading as System or Vendor Task
id: 2c7b9d14-6e3a-4f81-a5c2-7d1e9b4a6f83
status: experimental
description: Detects scheduled task creation referencing executables in user-profile, Temp, or ProgramData locations — a persistence pattern consistent with long-term implants such as NeedyMantis.
references:
- https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html
- https://attack.mitre.org/techniques/T1053/005/
author: Security Arsenal
date: 2026/09/15
tags:
- attack.persistence
- attack.privilege_escalation
- attack.t1053.005
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\schtasks.exe'
- '\powershell.exe'
- '\pwsh.exe'
CommandLine|contains:
- '/create'
- 'Register-ScheduledTask'
selection_suspicious_path:
CommandLine|contains:
- 'C:\\Users\\'
- 'AppData\\'
- 'C:\\Windows\\Temp\\'
- 'C:\\Temp\\'
filter_known:
CommandLine|contains:
- 'C:\\Users\\*\\AppData\\Local\\Microsoft\\Teams\\'
condition: selection and selection_suspicious_path and not filter_known
falsepositives:
- User-context application updaters (browsers, Teams, Slack)
- Developer tooling
level: medium
---
title: Rare Outbound HTTPS Connection from Non-Browser Process on Server
id: 4a1d8f62-9c5b-4e37-b2d8-6f3a1c7e9d24
status: experimental
description: Detects network connections to uncommon external destinations from processes that are not browsers or sanctioned agents — hunting logic for low-and-slow C2 beaconing characteristic of long-term implants like NeedyMantis.
references:
- https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html
- https://attack.mitre.org/techniques/T1071/001/
author: Security Arsenal
date: 2026/09/15
tags:
- attack.command_and_control
- attack.t1071.001
logsource:
category: network_connection
product: windows
detection:
selection:
DestinationPort:
- 443
- 8443
Initiated: 'true'
filter_browsers:
Image|endswith:
- '\chrome.exe'
- '\msedge.exe'
- '\firefox.exe'
- '\iexplore.exe'
filter_agents:
Image|contains:
- '\Windows Defender\\'
- '\Microsoft\\'
- '\CrowdStrike\\'
- '\SentinelOne\\'
condition: selection and not filter_browsers and not filter_agents
falsepositives:
- EDR, backup, and monitoring agents — build an allowlist of sanctioned agent paths
- Line-of-business application updaters
level: medium
Analyst note on the beaconing rule: The third rule is intentionally a hunting rule, not a high-fidelity alert. Run it as a scheduled analytic that aggregates by destination domain and process, then triage domains not seen elsewhere in the estate. A host beaconing to a domain that no other host in your environment contacts is a strong implant indicator.
KQL — Microsoft Sentinel / Defender Hunting Queries
Hunt 1: Persistence creation — services and scheduled tasks pointing at user-writable paths.
let Lookback = 14d;
DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| where FileName in~ ("sc.exe", "schtasks.exe", "powershell.exe", "pwsh.exe")
| where ProcessCommandLine has_any ("create", "binpath", "Register-ScheduledTask")
| where ProcessCommandLine has_any (@"C:\Users\", @"C:\ProgramData\", @"\AppData\", @"C:\Windows\Temp\")
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, ReportId
| sort by TimeGenerated desc
Hunt 2: Low-prevalence outbound HTTPS beaconing — candidate C2. This aggregates connections per device/process/domain and surfaces destinations seen on very few hosts, a classic implant signature.
let Lookback = 14d;
let KnownAgentPaths = dynamic([@"\Program Files\Microsoft\", @"\Program Files\CrowdStrike\", @"\Program Files\SentinelOne\", @"\Windows\System32\svchost.exe"]);
DeviceNetworkEvents
| where TimeGenerated > ago(Lookback)
| where RemotePort in (443, 8443)
| where ActionType == "ConnectionSuccess"
| where not(InitiatingProcessFolderPath has_any (KnownAgentPaths))
| where InitiatingProcessFileName !in~ ("chrome.exe", "msedge.exe", "firefox.exe")
| summarize Connections = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated)
by RemoteUrl, InitiatingProcessFileName, DeviceName
| summarize HostCount = dcount(DeviceName), TotalConnections = sum(Connections),
Processes = make_set(InitiatingProcessFileName), Earliest = min(FirstSeen)
by RemoteUrl
| where HostCount <= 2 and TotalConnections > 20
| sort by HostCount asc, TotalConnections desc
Hunt 3: File creation of unsigned executables in non-standard directories followed by execution — implant staging behavior.
let Lookback = 7d;
DeviceFileEvents
| where TimeGenerated > ago(Lookback)
| where FolderPath has_any (@"C:\ProgramData\", @"\AppData\Local\Temp\", @"C:\Windows\Temp\")
| where FileName endswith ".exe"
| join kind=inner (
DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| project ProcessTime = TimeGenerated, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, SHA256
) on DeviceName, FileName
| project FileCreateTime = TimeGenerated, ProcessTime, DeviceName, FileName, FolderPath, ProcessCommandLine, InitiatingProcessFileName, SHA256
| sort by FileCreateTime desc
Velociraptor VQL — Fleet-Wide Persistence Sweep
Deploy this as a hunt across all Windows endpoints to enumerate services and scheduled tasks whose binaries live outside sanctioned install directories — the two most common implant persistence surfaces.
-- Hunt: Persistence implant sweep — services/tasks with binaries in user-writable paths
-- Consistent with NeedyMantis-style long-term access implants
LET services = SELECT Name, DisplayName, PathName, StartName, State
FROM wmi(query="SELECT Name, DisplayName, PathName, StartName, State FROM Win32_Service")
WHERE PathName =~ '(?i)\\\\(Users|ProgramData|Windows\\\\Temp|Temp)\\\\'
AND NOT PathName =~ '(?i)Package Cache|Microsoft\\\\VisualStudio|Microsoft OneDrive'
LET taskfiles = SELECT Mtime AS ModTime, Size, FullPath
FROM glob(globs='C:/Windows/System32/Tasks/**/*', accessor='ntfs')
WHERE ModTime > Now() - 1209600 -- modified in last 14 days
SELECT * FROM services
-- Hunt: Processes executing from non-standard paths with established external connections
-- Candidate implant beaconing review
LET suspicious = SELECT Pid, Name, Exe, CommandLine, Username
FROM pslist()
WHERE Exe =~ '(?i)\\\\(Users|ProgramData|Windows\\\\Temp)\\\\'
AND NOT Exe =~ '(?i)OneDrive|Teams|Slack|Zoom|Google\\\\Chrome|AppData\\\\Local\\\\Programs'
SELECT suspicious.Pid AS Pid,
suspicious.Name AS Process,
suspicious.Exe AS Binary,
suspicious.Username AS User,
netstat().RaddrIP AS RemoteIP,
netstat().RaddrPort AS RemotePort,
netstat().Status AS ConnState
FROM suspicious
JOIN netstat() ON suspicious.Pid = netstat().Pid
WHERE netstat().Status =~ 'ESTAB'
AND netstat().RaddrIP !~ '^(10\\.|172\\.(1[6-9]|2[0-9]|3[01])\\.|192\\.168\\.|127\\.)'
PowerShell — Persistence Audit and Verification Script
Run this on endpoints (or via your RMM/Intune at scale) to enumerate the most common persistence surfaces an implant like NeedyMantis would abuse. Review output for anything your baseline does not recognize — do not auto-remove; preserve evidence first.
# NeedyMantis Persistence Surface Audit — Run as Administrator
# Output: CSV inventory of suspicious persistence artifacts for IR review
# NOTE: This script COLLECTS evidence. It does not delete anything.
$OutDir = "C:\IR-Collection\$env:COMPUTERNAME"
New-Item -ItemType Directory -Path $OutDir -Force | Out-Null
$SuspiciousRoots = @('C:\Users\','C:\ProgramData\','C:\Windows\Temp\','C:\Temp\','\AppData\')
$Allowlist = @('Package Cache','Microsoft\OneDrive','Microsoft\Teams','Microsoft\VisualStudio')
# 1. Services with binaries in user-writable paths
Write-Host "[*] Auditing services..." -ForegroundColor Cyan
Get-CimInstance Win32_Service | ForEach-Object {
$path = $_.PathName
if ($path -and ($SuspiciousRoots | Where-Object { $path -like "*$_*" })) {
if (-not ($Allowlist | Where-Object { $path -like "*$_*" })) {
[PSCustomObject]@{
Type = 'Service'; Name = $_.Name; DisplayName = $_.DisplayName
Path = $path; RunAs = $_.StartName; State = $_.State; StartMode = $_.StartMode
}
}
}
} | Export-Csv "$OutDir\services-suspicious.csv" -NoTypeInformation
# 2. Scheduled tasks executing from non-standard locations
Write-Host "[*] Auditing scheduled tasks..." -ForegroundColor Cyan
Get-ScheduledTask | ForEach-Object {
$task = $_
$_.Actions | Where-Object { $_.Execute } | ForEach-Object {
$exe = $_.Execute
if ($SuspiciousRoots | Where-Object { $exe -like "*$_*" }) {
if (-not ($Allowlist | Where-Object { $exe -like "*$_*" })) {
[PSCustomObject]@{
Type = 'ScheduledTask'; Name = $task.TaskName; Path = $exe
Arguments = $_.Arguments; State = $task.State; UserId = $task.Principal.UserId
}
}
}
}
} | Export-Csv "$OutDir\tasks-suspicious.csv" -NoTypeInformation
# 3. Run key / RunOnce entries pointing outside Program Files
Write-Host "[*] Auditing registry Run keys..." -ForegroundColor Cyan
$RunKeys = @(
'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run',
'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce',
'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run',
'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run',
'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce'
)
foreach ($key in $RunKeys) {
if (Test-Path $key) {
(Get-ItemProperty $key).PSObject.Properties | Where-Object {
$_.Name -notmatch '^PS' -and $_.Value -notmatch 'Program Files'
} | ForEach-Object {
[PSCustomObject]@{ Type = 'RunKey'; Key = $key; Name = $_.Name; Value = $_.Value }
}
}
} | Export-Csv "$OutDir\runkeys-audit.csv" -NoTypeInformation
# 4. Unsigned executables running from non-standard paths (live processes)
Write-Host "[*] Auditing running processes..." -ForegroundColor Cyan
Get-Process | Where-Object { $_.Path } | ForEach-Object {
$p = $_.Path
if ($SuspiciousRoots | Where-Object { $p -like "*$_*" }) {
if (-not ($Allowlist | Where-Object { $p -like "*$_*" })) {
$sig = Get-AuthenticodeSignature $p -ErrorAction SilentlyContinue
[PSCustomObject]@{
Type = 'Process'; Name = $_.ProcessName; PID = $_.Id; Path = $p
SignatureStatus = $sig.Status; Signer = $sig.SignerCertificate.Subject
}
}
}
} | Export-Csv "$OutDir\processes-suspicious.csv" -NoTypeInformation
# 5. Recent executable drops in staging directories (last 30 days)
Write-Host "[*] Scanning for recent executable drops..." -ForegroundColor Cyan
Get-ChildItem 'C:\ProgramData','C:\Windows\Temp' -Recurse -Include *.exe,*.dll -ErrorAction SilentlyContinue |
Where-Object { $_.CreationTime -gt (Get-Date).AddDays(-30) } |
Select-Object FullName, CreationTime, LastWriteTime, Length |
Export-Csv "$OutDir\recent-drops.csv" -NoTypeInformation
Write-Host "[+] Collection complete: $OutDir" -ForegroundColor Green
Write-Host "[!] PRESERVE these artifacts. Escalate anomalies to IR before remediation." -ForegroundColor Yellow
Remediation
Immediate Actions (0–24 hours)
- Hunt before you block. NeedyMantis is a post-compromise implant — a positive detection means an active intrusion with an unknown entry point. Treat any hit as a full IR engagement: isolate the host from the network (do not power off), capture memory, and preserve forensic images before remediation.
- Run the hunts above across your estate, prioritizing internet-facing infrastructure, identity systems (domain controllers, Entra ID/AD FS), and hosts in the targeted verticals' data flows (telecom core/OSS, research environments, contractor enclaves).
- Pull and review Microsoft threat intelligence. Apply the specific indicators of compromise (file hashes, C2 domains/IPs) from Microsoft's technical analysis to your EDR blocklists and network controls. Subscribe to Microsoft Threat Intelligence and The Hacker News source feed for indicator updates: https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html
- Assume credential compromise. If an implant is confirmed on any host, reset credentials for every account that has authenticated interactively to that machine — starting with privileged accounts. Review for newly created accounts and unexpected group membership changes.
Containment & Eradication (24–72 hours)
- Identify the initial access vector. Eradicating NeedyMantis without closing the entry point guarantees re-compromise. Audit edge devices (VPNs, firewalls, email gateways, remote access solutions) for exploitation, and review authentication logs for anomalous valid-account usage.
- Enumerate ALL persistence mechanisms. Dedicated implants are rarely deployed alone. Sweep for web shells on internet-facing servers, rogue scheduled tasks, service installations, WMI subscriptions, and Run key entries fleet-wide (the PowerShell script above covers the Windows surfaces).
- Rebuild, don't clean. For confirmed implant hosts, full reimage from known-good media is the only defensible eradication path against an adversary with months of dwell time.
- Rotate secrets at the environment level. Kerberos
krbtgt(twice), service account passwords, certificates accessible from compromised hosts, and any API keys or tokens stored on-disk.
Hardening (Ongoing)
- Attack Surface Reduction: Enable ASR rules blocking executable content from email clients, Office child processes, and execution from user-writable directories where feasible. Enforce WDAC/AppLocker policies restricting execution to sanctioned paths and publishers.
- Egress control: Implants depend on outbound C2. Enforce default-deny egress for servers (they have no business browsing the internet), proxy all user web traffic with TLS inspection and domain categorization, and alert on connections to newly registered or low-reputation domains.
- Identity hardening: Enforce phishing-resistant MFA (FIDO2) for all remote and privileged access, tier administrative accounts, and alert on privileged account use from unusual hosts or geographies.
- Detection coverage: Confirm your SIEM is ingesting Sysmon process creation, service installation (7045), scheduled task creation (4698/106), and network connection events — the detections above depend on them.
- Vendor and supply-chain review: Government contractors and telecoms should assess whether managed service providers, software updaters, or third-party remote access tooling represents the initial access path — this victimology pattern frequently involves trusted-relationship compromise.
If You Find It
Engage your incident response provider and legal counsel immediately. Given the victimology (intergovernmental organizations, government contractors, telecom), consider reporting obligations to CISA, relevant sector ISACs, and — for defense industrial base organizations — mandatory reporting under DFARS 252.204-7012. Do not tip off the adversary with visible blocking actions until your scoping is complete.
Related Resources
Security Arsenal Healthcare Cybersecurity AlertMonitor Platform Book a SOC Assessment healthcare Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.