A sophisticated cyber threat group has been exploiting a previously unknown vulnerability in compromised networks, allowing them to maintain long-term access and evade detection. The technique, dubbed NeedyMantis, involves leveraging exposed identities within breached organizations to create a perpetual backdoor into the network.
The hackers’ modus operandi is rooted in privilege escalation, where they identify a single vulnerable individual or account that can be used as a stepping stone to escalate privileges across multiple domains and systems. This technique allows them to bypass traditional security controls and maintain persistence within the compromised environment, often for months or even years without being detected.
The NeedyMantis attack vector relies on the exploitation of identity-based vulnerabilities, which are surprisingly common in many organizations. These include misconfigured directory services, improperly secured administrative accounts, or simply outdated passwords that have been exposed through data breaches. By targeting these vulnerable identities, hackers can create a ‘golden ticket’ to unlock access to sensitive areas of the network.
Once inside, the attackers use their privileged position to map the internal network and identify key choke points – essentially the critical infrastructure and data repositories that are most valuable to the organization. They then sever breach routes at these choke points, effectively creating a moat around the most sensitive areas, making it extremely difficult for security teams to detect or disrupt their activities.
The implications of NeedyMantis are significant: not only can hackers maintain long-term access to breached networks, but they also create a sense of false security among organizations. With traditional security measures in place, companies may believe they have protected themselves against more obvious types of attacks – only to find that the real threat lies within their own internal vulnerabilities.
In light of this revelation, it’s essential for organizations to prioritize identity management and access control. This involves implementing robust password policies, conducting regular privilege reviews, and ensuring that directory services are properly configured. Moreover, security teams should adopt a more proactive approach to monitoring for signs of privilege escalation and identity-based attacks, rather than relying solely on traditional threat detection methods.
Source: The Hacker News — 2026-09-28