Microsoft Threat Intelligence has revealed a new malware family it named NeedyMantis, which operates as a modular post-compromise framework. Rather than being used for initial access to a network, it is typically deployed after an attacker has established a foothold within the environment, with the aim of maintaining access for extended periods and supporting subsequent operations.
According to Microsoft, NeedyMantis activity dates back to at least October 2025. The company discovered the family while analyzing indicators associated with the DAEMON Tools supply-chain compromise, which Kaspersky previously covered, but it confirms that it has not observed NeedyMantis itself being distributed through a supply-chain compromise. Microsoft also linked the observed activity to China-based entities, without asserting that all cases are attributable to the same operator or to a Chinese government entity.
Limited Targeting and Selective Distribution
NeedyMantis appeared in compromises affecting telecommunications organizations, universities, nonprofit medical organizations, international governmental organizations, and government contractors. Microsoft believes that the victim pattern and the small number of observed deployment cases indicate selective use rather than a widespread campaign.
Microsoft observed at least one operator using the family: Storm-3069, the name the company uses for activity associated with the DAEMON Tools compromise. However, it also identified additional activity, leaving open the possibility that NeedyMantis is being used by more than one operator.
How Does NeedyMantis Work?
The family consists of components written in C++ and x64 shellcode, and it usually begins with an initial loader and a custom file archive. The loader masquerades as a DLL required by a legitimate program and is then executed through DLL sideloading. Microsoft observed the use of names associated with programs such as Poedit, curl, Vim, and TightVNC, in addition to names impersonating components from Microsoft Office, Broadcom, Intel, and NVIDIA.
The loader extracts the second stage from an encrypted archive compressed using a custom structure. The archive includes legitimate components alongside malicious files responsible for loading the main component and storing configuration and communications. In one analyzed sample, a file named encryptbase64.ps1 carried x64 shellcode rather than being a conventional PowerShell script, and then decompressed an executable component in a custom format derived from PE.
The main component uses a command-and-control (C2) channel based first on HTTPS and then on WebSockets, and sends information such as the device name, user, processes, and programs located in the ProgramFiles folder. It also supports commands to load and remove additional modules and pass data to them, giving the framework extensibility whose detailed capabilities have not yet been fully determined.
Why Does This Matter?
NeedyMantis is significant because it combines masquerading within legitimate programs, encrypted archives, multiple loading stages, and extensible components. This structure alone does not prove the presence of specific espionage capabilities in every sample, but it makes detecting and analyzing the activity more difficult, particularly when deployment occurs after an existing compromise. The family’s reliance on DLL sideloading also means that monitoring file names alone may not be sufficient; the legitimate program’s path, process behavior, and external communications should also be correlated.
Detection and Mitigation Guidance
Microsoft recommended monitoring outbound connections to the domain corp.tripswithengine[.]com and searching for the user agent Firefox/21.0 associated with one of the communication components. It also published Advanced Hunting queries for Microsoft Defender XDR and Microsoft Sentinel to detect DLL names and paths associated with the family.
The recommendations include enabling cloud-delivered protection and the block-at-first-sight feature, running EDR in block mode, and enabling Network Protection and Automatic Attack Disruption, along with Attack Surface Reduction rules to prevent untrusted executables and the execution of obfuscated scripts. Microsoft also provides indicators of compromise, detections, and threat reports associated with NeedyMantis, Storm-3069, and Impacket.