NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

"Prevention is cheaper than a breach"

Microsoft Threat Intelligence has identified NeedyMantis, a modular, post-compromise malware family primarily used to maintain long-term access within targeted environments. Since at least October 2025, this malware has been deployed against telecommunications, academic, medical, and governmental organizations. Often associated with the threat actor Storm-3069, NeedyMantis is typically introduced post-compromise, leveraging DLL sideloading and custom file archives to evade detection.

Architecture and Capabilities

NeedyMantis is characterized by a sophisticated, multi-stage architecture:

  • First-Stage Loader: A DLL masquerading as legitimate software (such as Poedit, curl, or Vim) that utilizes obfuscated stack strings and anti-debugger checks.
  • Custom File Archives: An encrypted and compressed container format that holds the malware’s modular components, including its main executable, configuration files, and communication libraries.
  • Main Component: Orchestrates Command-and-Control (C2) communications and allows for the dynamic loading/unloading of additional modules.
  • C2 Communications: Employs a binary protocol over WebSockets, often spoofing legitimate Windows networking libraries (e.g., ws2_32.dll) and using hard-coded User-Agents like ‘Firefox/21.0’ to blend in with standard traffic.

Distribution and Evasion

NeedyMantis is not typically distributed via a supply chain, but rather deployed manually by threat actors after they have already gained initial access. Operators often use tools like Impacket to move these malicious packages laterally within a victim’s network. The malware relies heavily on custom executable formats and runtime API resolution to hinder security analysis.

Mitigation and Defense

Organizations are encouraged to adopt the following measures to defend against NeedyMantis:

  • Network Monitoring: Block and monitor outbound connections to the known C2 domain corp.tripswithengine[.]com.
  • Defender Protections: Enable Microsoft Defender for Endpoint with ‘EDR in block mode’ and configure Attack Surface Reduction (ASR) rules to block suspicious executable files and obfuscated scripts.
  • Hunting: Utilize the provided advanced hunting queries for Microsoft Defender XDR and Sentinel to identify the presence of malicious sideloaded DLLs and unexpected network patterns.

For a complete list of Indicators of Compromise (IOCs) and detailed detection logic, organizations should review the full threat intelligence report, which includes specific file hashes and behavioral analytics.

Leave A Comment

Name*
Message*

Scroll to top