Microsoft’s disclosure of NeedyMantis provides a useful look at the kind of malware attackers deploy after the noisy part of an intrusion is already over. Unlike commodity malware designed to infect as many systems as possible, NeedyMantis appears to be a selectively deployed post-compromise framework intended to preserve access, maintain command-and-control, and give operators the ability to load additional modules as required.

Microsoft says the malware has been observed since at least October 2025 in a limited number of intrusions affecting telecommunications organizations, universities, intergovernmental organizations, medical nonprofits, and government contractors. That victim profile, combined with the malware’s selective deployment and long-term persistence design, is more consistent with targeted intelligence-gathering operations than broad financially motivated malware distribution.

Microsoft has observed at least one actor, tracked as Storm-3069, using NeedyMantis. Storm-3069 is associated with activity connected to the earlier DAEMON Tools supply-chain compromise. Microsoft assesses that the activity originates from China, but it has not attributed Storm-3069 to a Chinese government or nation-state organization. Microsoft has also observed NeedyMantis outside activity directly connected to Storm-3069, which raises the possibility that more than one operator may have access to the framework.

That attribution nuance is important. The targeting, operational style, and infrastructure may align with activity Microsoft associates with China-based actors, but the evidence currently supports saying China-linked or China-based activity, not definitively naming a state sponsor.

One of the most important defensive lessons is that NeedyMantis typically appears after initial compromise. Microsoft specifically says the method used to gain access may vary from intrusion to intrusion. In one observed case, an attacker already operating inside the victim environment used the Impacket toolkit to copy legitimate software, a malicious DLL, and the NeedyMantis archive from a network share onto another system and then execute it.

This means NeedyMantis should be treated as evidence of a deeper intrusion, not a standalone malware event.

If defenders discover the implant on one endpoint and simply delete the files, they may remove only one persistence mechanism while leaving intact the stolen credentials, lateral-movement paths, remote-access infrastructure, or other footholds the attacker used to deploy it in the first place.

The deployment technique is also deliberately designed to blend into normal software environments. NeedyMantis uses DLL sideloading, where legitimate software is placed alongside a malicious DLL carrying the name of a library the application expects to load. When the trusted executable launches, Windows loads the attacker-controlled DLL from the local directory.

Microsoft observed NeedyMantis packaged alongside software including Poedit, curl, Vim, and TightVNC, while malicious components were also disguised using names associated with Microsoft Office, Broadcom, Intel, and NVIDIA. Examples include WinSparkle.dll, libcurl.dll, vim64.dll, dbghelp.dll, jli.dll, and nvml.dll.

This technique is effective because the executable itself may be legitimate and properly signed. Detection that focuses only on whether the parent application is trusted can therefore miss the malicious library being loaded beside it.

The attack chain becomes something like:

existing attacker access → legitimate software copied to target → malicious replacement DLL placed beside it → legitimate executable runs → malicious DLL is sideloaded → NeedyMantis loader executes → custom archive unpacked → main implant activated

Nothing in that chain requires the attacker to replace the trusted application itself.

The malicious DLL simply takes advantage of how the application resolves its dependencies.

The NeedyMantis packaging architecture adds several layers intended to make analysis harder. The first-stage loader extracts data from a custom file archive whose contents are XOR-decoded and decompressed using Windows RtlDecompressBuffer. The structure, offsets, keys, and values vary between samples, reducing the usefulness of simple static signatures.

Some archives contain multiple legitimate files mixed with malicious components. One analyzed archive contained legitimate 7-Zip and Sysinternals binaries alongside malicious files masquerading as Windows networking libraries.

That blending of genuine software with custom malware is a recurring theme in targeted intrusions because it creates both analytical noise and detection ambiguity.

The second-stage component is even more interesting. A file named encryptbase64.ps1 appears to be a PowerShell script based on its extension, but Microsoft found that it actually contains x64 shellcode rather than normal PowerShell code. Its purpose is to extract, decode, and decompress the main NeedyMantis component.

The loader dynamically resolves Windows APIs using hashed names and a configurable rotate-right algorithm, and the embedded data locations and XOR keys shift from sample to sample. These are not groundbreaking techniques individually, but together they make static inspection more cumbersome and hinder simple signature-based detection.

The main component is stored in a custom minimized executable format rather than a conventional Portable Executable structure. This again complicates automated analysis because many defensive and forensic tools expect standard PE headers and layouts.

Once active, NeedyMantis creates a mutex based on the username and process name and initializes its command-and-control configuration. Microsoft found one sample configured to communicate with:

corp.tripswithengine[.]com

over port 443 using a URI resembling:

/library/zip/

The malware first sends an HTTPS GET request and embeds host information in a cookie-like field. That information can include the computer name, username, process name, parent process, installed files under Program Files, and process list.

The communication then upgrades into a WebSocket connection, which gives NeedyMantis a persistent bidirectional channel between the victim and the command-and-control server.

That use of HTTPS followed by WebSockets is notable because both protocols are normal in modern enterprise traffic. Many legitimate web applications, collaboration systems, dashboards, and cloud services use WebSockets, making protocol-based blocking alone impractical.

The malware’s communication component uses either Windows WinINet APIs or, in other observed versions, the Libwebsockets library. The initial connection appears as HTTPS traffic before transitioning into a custom binary WebSocket protocol.

This highlights why encrypted traffic inspection and behavioral network analytics are increasingly important. A connection using TCP 443 and WebSockets is not suspicious by itself. The relevant context is which executable opened the connection, where it connected, how frequently it communicates, and whether the destination makes sense for that process.

The custom NeedyMantis C2 protocol adds further obfuscation. Communications use compression, XOR encoding, and in some cases RC4 encryption. During the initial key exchange, the malware generates random data, derives an RC4 key, embeds the string google.com inside an encrypted buffer, and sends it along with randomized padding.

This kind of protocol design serves multiple purposes. It makes the network traffic less immediately readable, complicates static packet signatures, and gives the C2 server a way to verify that it is communicating with the expected implant.

The main NeedyMantis component itself has relatively few commands, but that simplicity is intentional. Microsoft found commands for sending host information, maintaining the connection, loading modules, unloading modules, and dispatching data to loaded modules.

The architecture therefore resembles a modular implant platform rather than a monolithic backdoor.

The core implant provides communication and module management.

The operator can add whatever functionality is needed later.

That design has important implications for defenders because the absence of credential theft, file exfiltration, screenshot capture, or lateral-movement functionality in the core NeedyMantis binary does not mean the attacker lacks those capabilities.

Microsoft explicitly says the capabilities of the additional modules remain unconfirmed.

A modular architecture gives the operator the flexibility to deploy only the tools necessary for a particular victim, reducing unnecessary functionality and potentially lowering detection risk.

Older NeedyMantis versions also contained a module specifically used to establish persistence through Windows Services.

That persistence mechanism is straightforward but effective. A service can automatically start at boot and run under privileged accounts, providing reliable long-term execution. The presence of an older Windows Services module also supports Microsoft’s assessment that NeedyMantis is designed to maintain durable access rather than act only as a temporary remote shell.

The malware’s development history is also notable. Microsoft’s samples show changes in archive structure, communication components, filenames, and packaging between versions. An older variant used a small archive containing only four components, while newer builds bundle a much larger set of legitimate and malicious files.

That evolution suggests active development and operational refinement rather than abandoned or one-off tooling.

From a threat-hunting perspective, DLL sideloading creates one of the best opportunities for detection. Security teams should look for legitimate applications unexpectedly loading libraries from writable or unusual directories, particularly where the DLL name normally belongs to a legitimate component but its hash, signer, size, or creation time differs from the expected version.

The Microsoft-observed paths are useful starting points, including combinations such as Poedit with WinSparkle.dll, Vim with vim64.dll, and unexpected copies of dbghelp.dll, jli.dll, or nvml.dll under ProgramData or unusual application directories.

However, defenders should avoid relying exclusively on those filenames.

DLL sideloading techniques are flexible, and attackers can rename components or abuse different applications.

The more durable hunting logic is behavioral:

trusted executable + unexpected locally loaded DLL + suspicious recently created archive or shellcode + outbound encrypted connection to unusual infrastructure

That pattern survives far more easily than an IOC list.

Security teams should also hunt for Impacket activity, especially where tools such as SMBExec, WMIExec, or related mechanisms are used to transfer or execute files across internal systems. Microsoft specifically observed Impacket during hands-on-keyboard follow-on activity associated with a NeedyMantis deployment.

The presence of Impacket alone does not prove malicious activity because penetration testers and administrators may legitimately use it, but in an environment where Impacket is not expected, its appearance deserves immediate attention.

Network hunting is equally important. Microsoft recommends looking for outbound connections to the known C2 infrastructure and monitoring unusual HTTPS/WebSocket activity from processes that normally would not maintain persistent external connections.

Long-lived WebSocket sessions from executables such as Poedit, Vim, TightVNC-related binaries, or unfamiliar copies of legitimate software should therefore be investigated in context.

The victimology also deserves attention. Telecommunications organizations, universities, government contractors, intergovernmental bodies, and medical nonprofits often possess information with strategic value: communications metadata, research, policy documents, government relationships, scientific work, and sensitive organizational information.

These are precisely the kinds of environments where an attacker benefits from quiet, durable access over months rather than immediate financial monetization.

That operational pattern also explains why NeedyMantis does not need a spectacular feature list. A stealthy modular foothold with reliable command-and-control may be more valuable to an intelligence-oriented operator than ransomware or noisy credential-stealing malware.

The apparent connection to the earlier DAEMON Tools compromise should also be interpreted carefully.

Microsoft discovered NeedyMantis while pivoting from indicators associated with Kaspersky’s investigation of that supply-chain campaign, and Storm-3069 is connected to that activity. However, Microsoft explicitly states that it has not observed NeedyMantis itself being distributed through the DAEMON Tools supply chain.

That distinction matters.

A related actor does not automatically imply an identical delivery mechanism.

Supply-chain compromise may be one route through which an attacker gains initial access, but NeedyMantis is the tool used afterward to establish longer-term access.

For defenders, that means discovering NeedyMantis should trigger retrospective investigation far beyond the malware installation date.

Teams should reconstruct the timeline and ask:

When did the attacker first enter the network?

Which account or system was compromised first?

What credentials were stolen?

What lateral movement occurred?

Was remote access established elsewhere?

Did the attacker access sensitive files or databases?

Were additional persistence mechanisms deployed?

Was any data staged or exfiltrated?

The earliest NeedyMantis timestamp may represent only the moment the attacker decided to stay, not the moment they first arrived.

That difference is crucial during incident response.

The malware’s modular command system also means forensic teams should search for downloaded payloads, unusual DLLs, scripts, temporary archives, memory-resident code, and service modifications surrounding the NeedyMantis execution period. Removing the core implant without identifying additional loaded modules may leave portions of the attack chain undiscovered.

Credential rotation should also be considered if the affected system handled privileged credentials or if the attacker had interactive access before deployment. Because NeedyMantis is post-compromise malware, it should generally be assumed that the actor may already have obtained authentication material before the framework appeared.

This is why post-compromise malware demands a different response from commodity infection.

With a simple downloader, the question may be:

“What did this malware install?”

With NeedyMantis, the more useful question is:

“What level of access did the attacker already have before they decided to install this?”

The broader cybersecurity lesson from NeedyMantis is that persistence malware is increasingly designed as infrastructure rather than a single-purpose tool.

Its job is not necessarily to steal data immediately.

Its job is to keep the attacker connected, remain difficult to analyze, and provide a reliable platform for whatever operation comes next.

The architecture can be summarized as:

existing compromise → hands-on-keyboard deployment → legitimate application + malicious DLL → DLL sideloading → custom encrypted archive → shellcode loader → modular NeedyMantis implant → HTTPS/WebSocket C2 → additional modules on demand

Each layer makes the intrusion slightly harder to understand and slightly easier for the operator to adapt.

The most important lesson for security teams is therefore not merely to block one domain or one DLL hash.

Finding NeedyMantis means the investigation should move backward as well as forward.

Forward, to determine what modules or actions came next.

Backward, to identify how the attacker reached the point where deploying a long-term persistence framework was possible.

The malware is dangerous not because it represents the beginning of the attack.

It is dangerous because it suggests the attacker had already decided the victim was worth keeping.


Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use goes back to at least

Source: Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks via The Hacker News — published 28 Sep 2026.