Microsoft Uncovers NeedyMantis, a Modular Implant for Long-Term Network Access
Microsoft Threat Intelligence has published a technical breakdown of NeedyMantis, a modular post-compromise malware family that attackers have used to preserve covert, long-term access inside networks they had already breached. In a report published September 28, 2026, Microsoft says it identified NeedyMantis in a small number of targeted intrusions against telecommunications organizations, universities, medical nonprofits, intergovernmental bodies, and government contractors, with activity dating back to at least October 2025. Microsoft found the malware while pivoting from indicators tied to Kaspersky's investigation into the DAEMON Tools supply-chain compromise, and links at least one deployment to Storm-3069, its designation for the activity cluster behind that supply-chain incident.
Critically, Microsoft says it has not observed NeedyMantis itself being delivered through the compromised DAEMON Tools installers. The available evidence indicates operators drop NeedyMantis only after they already have a foothold in a victim environment — meaning the initial access vector can and does differ from victim to victim. That makes NeedyMantis a persistence and follow-on-operations tool, not an initial-access weapon, and its selective, narrow targeting pattern points toward espionage rather than broad financially motivated cybercrime.
Incident Details
| Attribute | Value |
|---|---|
| Malware family | NeedyMantis |
| Reported by | Microsoft Threat Intelligence |
| Malware type | Modular post-compromise implant (C++ and x64 shellcode) |
| Associated actor | Storm-3069 — Microsoft assesses the activity as China-based but has not attributed it to a specific nation-state group, and notes more than one operator may possess the malware |
| Primary delivery technique | DLL sideloading via a bundle of legitimate software, a malicious DLL, and an encrypted archive |
| Targeted sectors | Telecommunications, universities, medical nonprofits, intergovernmental organizations, government contractors |
| Earliest observed activity | At least October 2025 |
| Discovery path | Follow-on analysis of indicators from Kaspersky's DAEMON Tools (Storm-3069) supply-chain investigation |
| Observed C2 infrastructure | corp.tripswithengine[.]com, port 443, URI path /library/zip/ |
| Defender detection names | TrojanDropper:Win64/NeedyMantis, Behavior:Win64/NeedyMantis |
| Publication date | September 28, 2026 |
How NeedyMantis Works
A Three-Part Bundle and DLL Sideloading
NeedyMantis arrives as three files dropped together: a copy of a legitimate program, a malicious DLL named after a file that program normally loads at startup, and an encrypted archive sharing the DLL's filename. When the legitimate program launches, Windows loads the malicious DLL in place of the real one — a technique known as DLL sideloading. Microsoft observed the legitimate-software cover including the Poedit translation tool, curl, the Vim text editor, and the TightVNC remote-access tool, with the malicious DLL also masquerading as components belonging to Microsoft Office, Broadcom, Intel, and NVIDIA. In the sample Microsoft analyzed in the greatest depth, the malicious file replaced WinSparkle.dll, the update component normally used by Poedit.
Multi-Stage Unpacking Designed to Resist Analysis
Once loaded, the malicious DLL — the first-stage loader — pulls the next stage out of the accompanying encrypted archive. The archive's offsets, XOR keys, compression parameters, and internal filenames vary between samples, which complicates both static signature detection and automated sandbox analysis. That second stage decodes NeedyMantis's main component, which is responsible for command-and-control (C2) communication and for loading additional functionality on demand.
Command-and-Control: HTTPS Beacon, Then a WebSocket Pivot
The main component first reaches out over HTTPS, embedding compressed and Base64-encoded host information — computer name, username, running and parent processes, installed software, and process listings — inside the request's cookie data. After this initial check-in, the connection upgrades to a WebSocket session using a custom binary protocol that combines XOR encoding, compression, and, in some configurations, RC4 encryption. Over that channel, NeedyMantis can receive instructions to load or unload modules, receive and dispatch data to those modules, and toggle off active flags, while periodically sending identification and keepalive messages back to the operator. Microsoft says it has not fully confirmed the capabilities of the modules that can be pushed down this channel, but the architecture itself is the point: operators can extend the implant's functionality without ever replacing the core malware already sitting on the host, an efficient design for sustained, adaptable access.
Hands-on-Keyboard Deployment
In one intrusion Microsoft examined, an operator already present in the environment used the post-exploitation tool Impacket to copy the legitimate-program-plus-DLL-plus-archive bundle from a network share directly onto a targeted device. That detail reinforces Microsoft's framing of NeedyMantis as a post-compromise tool: it is staged and executed by an actor who has already achieved access, rather than being the mechanism that gets them in.
Impact Assessment
| Impact Area | Description |
|---|---|
| Persistence risk | NeedyMantis is purpose-built to keep operators inside a network long after the original intrusion vector may have been patched or noticed |
| Detection difficulty | Varying archive offsets/keys per sample, DLL sideloading against trusted software, and an HTTPS-to-WebSocket C2 pivot are all designed to blend into normal traffic and evade static detection |
| Espionage exposure | Narrow targeting of telecom, academic, nonprofit, intergovernmental, and government-contractor victims points to intelligence-gathering rather than opportunistic financial crime |
| Attribution uncertainty | Microsoft ties at least one deployment to Storm-3069 but stops short of nation-state attribution and flags that multiple operators may be using the malware |
| Extensibility risk | The undisclosed module-loading capability means the full scope of what an infected host can be made to do is not yet completely known |
| Supply-chain adjacency | While NeedyMantis was not delivered via the compromised DAEMON Tools installers, its discovery through that investigation shows how one supply-chain incident can surface unrelated, previously unseen malware during follow-on hunting |
Recommendations
For Security Teams and Threat Hunters
- Hunt for DLL sideloading behavior on hosts running Poedit, curl, Vim, or TightVNC, and treat unexpected DLLs named after Office, Broadcom, Intel, or NVIDIA components as high-priority alerts.
- Monitor for outbound connections to
corp.tripswithengine[.]comand, more broadly, for HTTPS sessions that pivot to WebSocket connections shortly after establishment. - Use Microsoft's published hunting queries for Microsoft Defender XDR to search historical telemetry for NeedyMantis indicators, since the malware has been active since at least October 2025 and may already be present undetected.
- Flag use of Impacket and other lateral-movement tooling for copying files from network shares, particularly bundles containing an executable, a same-named DLL, and an archive.
For System Administrators
- Enable cloud-delivered protection and block-at-first-sight in Microsoft Defender Antivirus so novel sideloaded DLLs are evaluated against cloud signal rather than local signatures alone.
- Turn on network protection and run EDR in block mode to allow automatic remediation of malicious artifacts even when a third-party antivirus is the primary defense.
- Enable automatic attack disruption in Microsoft Defender XDR to contain compromised devices faster once sideloading or C2 activity is detected.
- Apply attack surface reduction (ASR) rules that block execution of files lacking prevalence, age, or trusted-list criteria, and that block obfuscated script execution — both rules directly counter NeedyMantis's loader and archive-unpacking behavior.
For Affected-Sector Organizations
- Telecom operators, universities, medical nonprofits, intergovernmental bodies, and government contractors should treat this report as a signal to review software update mechanisms (WinSparkle-style updaters and similar components) for tampering, since these are exactly the files NeedyMantis's loader impersonates.
- Inventory instances of Poedit, curl, Vim, and TightVNC across the environment and verify the integrity of their associated DLLs against known-good hashes.
- Given the espionage-oriented targeting pattern, prioritize detection engineering and retrospective hunting over relying solely on preventive controls — Microsoft's own findings suggest this malware is built to stay hidden.
Key Takeaways
- NeedyMantis is a post-compromise persistence tool, not an initial-access malware — Microsoft has not seen it delivered through the DAEMON Tools supply-chain compromise that led researchers to discover it, and evidence shows it is deployed only after attackers already have a foothold.
- DLL sideloading is the core delivery mechanism, abusing trusted software including Poedit, curl, Vim, and TightVNC, plus DLL names borrowed from Microsoft Office, Broadcom, Intel, and NVIDIA components.
- The malware is modular, using an HTTPS-to-WebSocket C2 pivot with optional RC4 encryption to load and unload additional capability without replacing the core implant.
- Targeting is narrow and espionage-shaped: telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors, active since at least October 2025.
- Attribution remains partial — Microsoft links the activity to Storm-3069 and assesses a China-based origin, but has not tied it to a specific nation-state actor and notes multiple operators may be involved.
- Defenders should hunt now, not just patch — Microsoft's published IOCs, C2 domain, and Defender XDR hunting queries give organizations a way to retroactively check for infections that may already have been sitting quietly on their networks for months.