Microsoft: NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

Microsoft: NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

Microsoft Uncovers NeedyMantis: A Modular Post-Compromise Malware Targeting High-Value Sectors

Microsoft Threat Intelligence has identified NeedyMantis, a sophisticated post-compromise malware family used in targeted operations against telecommunications providers, universities, medical nonprofits, intergovernmental organizations, and government contractors. First observed in October 2025, the malware is deployed after threat actors have already established access to a victim’s environment, enabling long-term persistence and follow-on attacks.

Attribution and Threat Actors

NeedyMantis activity aligns with operations linked to China-based threat actors, though Microsoft has not attributed it to a specific nation-state group. The malware has been associated with Storm-3069, a threat actor tied to the DAEMON Tools supply chain compromise previously reported by Kaspersky. However, additional NeedyMantis activity suggests it may be shared among multiple operators, all exhibiting targeting patterns consistent with Chinese cyberespionage interests.

Malware Architecture and Evasion Techniques

NeedyMantis is a modular framework designed to evade detection and extend functionality through custom components. Key features include:

  • Multi-stage loaders: The malware begins with a DLL sideloading technique, masquerading as legitimate software (e.g., Poedit, curl, Vim, TightVNC, or vendor-specific DLLs like Microsoft Office, Intel, or NVIDIA components).
  • Custom file archives: Encrypted and compressed archives contain both legitimate binaries (e.g., 7-Zip, Sysinternals tools) and malicious payloads, including a second-stage PowerShell-based loader (despite its .ps1 extension, it executes x64 shellcode).
  • Anti-analysis measures: Obfuscated strings, dynamic API resolution, anti-debugging checks (e.g., ProcessDebugFlags, ThreadHideFromDebugger), and custom executable formats hinder reverse engineering.
  • Command-and-control (C2) communications: Uses WebSockets over HTTPS, with initial beacons containing system metadata (e.g., computer name, username, process list). A binary protocol handles encrypted data exchange, including a key exchange mechanism and modular command execution.

Deployment and Victimology

NeedyMantis is selectively deployed in post-compromise scenarios, often introduced via:

  • DLL sideloading (e.g., replacing WinSparkle.dll in Poedit or libcurl.dll in data transfer tools).
  • Hands-on-keyboard activity (e.g., using Impacket to copy malicious files from network shares).
  • Supply chain vectors (though not directly observed, prior access via supply chain compromises remains plausible).

Victims span telecommunications, academia, intergovernmental bodies, medical nonprofits, and government contractors, suggesting a focus on high-value intelligence targets.

C2 Infrastructure and Capabilities

  • Primary C2 domain: corp.tripswithengine[.]com (port 443, URI /library/zip/).
  • Hard-coded user-agent: firefox/21.0.
  • Modular design: Supports dynamic loading/unloading of additional modules (e.g., persistence via Windows Services), though their specific functions remain unconfirmed.
  • Commands: Includes keep-alive signals, module management, and data dispatch to extend functionality.

Indicators of Compromise (IOCs)

Microsoft has released SHA-256 hashes for key components:

  • First-stage loader: e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e (WinSparkle.dll).
  • Custom file archives: 9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef (WinSparkle), c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77 (libcurl).
  • C2 domain: corp.tripswithengine[.]com.

NeedyMantis exemplifies the evolving tactics of post-compromise malware, combining stealth, modularity, and targeted deployment to maintain access in high-value environments. Its alignment with China-linked threat actors underscores the ongoing risk to sectors critical to geopolitical and economic intelligence.

Source: https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/

Microsoft TPRM report: https://www.rankiteo.com/company/microsoft-threat-intelligence

"id": "mic1790663487",
"linkid": "microsoft-threat-intelligence",
"type": "Cyber Attack",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Telecommunications',
                        'type': 'Telecommunications providers'},
                       {'industry': 'Education', 'type': 'Universities'},
                       {'industry': 'Healthcare', 'type': 'Medical nonprofits'},
                       {'industry': 'Government',
                        'type': 'Intergovernmental organizations'},
                       {'industry': 'Defense/Contracting',
                        'type': 'Government contractors'}],
 'attack_vector': ['DLL sideloading',
                   'Hands-on-keyboard activity',
                   'Supply chain vectors'],
 'date_detected': '2025-10',
 'description': 'Microsoft Threat Intelligence has identified NeedyMantis, a '
                'sophisticated post-compromise malware family used in targeted '
                'operations against telecommunications providers, '
                'universities, medical nonprofits, intergovernmental '
                'organizations, and government contractors. The malware is '
                'deployed after threat actors have already established access '
                'to a victim’s environment, enabling long-term persistence and '
                'follow-on attacks.',
 'investigation_status': 'Ongoing',
 'motivation': 'Cyberespionage',
 'post_incident_analysis': {'root_causes': 'Post-compromise deployment via DLL '
                                           'sideloading, hands-on-keyboard '
                                           'activity, or supply chain vectors'},
 'references': [{'source': 'Microsoft Threat Intelligence'},
                {'source': 'Kaspersky (DAEMON Tools supply chain compromise)'}],
 'threat_actor': ['China-based threat actors', 'Storm-3069'],
 'title': 'Microsoft Uncovers NeedyMantis: A Modular Post-Compromise Malware '
          'Targeting High-Value Sectors',
 'type': 'Malware Deployment'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.