A sophisticated hacking group has been using a malware tool called NeedyMantis to maintain long-term access in breached networks, allowing them to launch subsequent attacks and evade detection. The malware’s ability to bypass traditional security measures makes it a particularly concerning threat for organizations with sensitive data.
NeedyMantis operates by exploiting vulnerabilities in network management protocols, specifically targeting devices that rely on cross-domain privilege escalation (CPE) mechanisms. CPE allows administrators to manage multiple domains from a single console, but it also creates a vulnerability when exploited by attackers. By manipulating the CPE protocol, NeedyMantis enables hackers to move laterally within a network, creating a persistent backdoor for future attacks.
The use of NeedyMantis has been linked to several high-profile breaches in recent months, with multiple organizations across various industries affected. The malware’s ability to remain undetected for extended periods makes it particularly challenging for security teams to respond effectively. According to sources, the hackers behind NeedyMantis have been using the tool to gather sensitive information and create a network of compromised systems that can be used for future attacks.
One key aspect of NeedyMantis is its ability to map cross-domain privilege escalation to sever breach routes at key choke points. This allows the attackers to identify vulnerabilities in the network and create multiple entry points, making it harder for security teams to contain the damage. By creating a network of compromised systems, the hackers can also use them as launchpads for future attacks, further increasing the risk of data breaches.
The use of NeedyMantis highlights the importance of robust network segmentation and CPE protocol management. Organizations must ensure that their networks are properly segmented to limit the spread of malware in case of a breach. Additionally, regular security audits and vulnerability assessments can help identify potential entry points for attackers like those using NeedyMantis.
To protect against this type of threat, organizations should prioritize secure network design and robust access controls. Regularly monitoring network traffic for suspicious activity and implementing endpoint detection and response (EDR) solutions can also help detect and contain malware infections early on. Furthermore, employees should be educated about the importance of CPE protocol management and cross-domain privilege escalation best practices to prevent accidental vulnerabilities in their networks.
Source: The Hacker News — 2026-09-28