A modular malware family dubbed NeedyMantis has been identified by Microsoft Threat Intelligence, and has been employed to maintain access to compromised systems in a limited number of targeted intrusions.
Evidence of the malware dating back to at least October 2025 indicates that it has affected telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors.
During an investigation into indicators associated with the DAEMON Tools supply chain compromise, Microsoft identified NeedyMantis.
The company tracks activity associated with Storm-3069, and has observed the malware in use beyond that campaign.
While Microsoft believes the observed operations are associated with activities associated with China-based threat actors, it has not attributed Storm-3069 to a Chinese nation state actor or confirmed that all NeedyMantis activity originated from a single operator.
As a general rule, NeedyMantis is deployed after attackers have already gained access to the target environment.
The malware serves primarily as an initial access tool, but it is also intended to maintain access and facilitate further activity within the compromised network, utilizing DLL sideloading as part of its delivery chain. It has been observed that attackers packaged malicious DLLs with legitimate applications and encrypted archives in an attempt to facilitate their delivery.
Poedit, curl, Vim, and TightVNC were among the programs abused in this manner, while malicious DLLs were disguised as Microsoft Office, Broadcom, Intel, and NVIDIA components. One incident involved the use of Impacket toolkit to copy a legitimate software package from a network share into the malicious file, which was then executed on the targeted computer.
It is important to note that NeedyMantis played a crucial role in the post-compromise phase of an intrusion, despite the attacker already having established access to the environment.
Once the initial DLL is loaded, the malware continues to feature layered security. A second-stage component is extracted from the encrypted archive by the first-stage loader, which is the file used in the analysis, encryptbase64.ps1.
Even though the file has a PowerShell extension, it contains x64 shellcode rather than a conventional PowerShell script.
Once the embedded malware has been decoded and decompressed, a custom executable format based on a reduced version of the Windows PE format is loaded.
An additional level of protection can be provided by the custom archive. Its contents can vary between samples, with file names and internal values varying.
The analyzed WinSparkle archive contained legitimate components of 7-Zip and Sysinternals as well as files with familiar Windows library names, including dnsapi.dll and ws2_32.dll, mixed with legitimate components.
Instead of the legitimate libraries represented by these files, NeedyMantis configuration and communication components were found in these files. The main component communicates with the malware's command-and-control infrastructure and manages additional modules.
It is Microsoft's responsibility to observe an initial HTTPS request before switching the connection to a binary WebSocket protocol. The communications component utilizes WebSockets.
A hard-coded user agent for Firefox 21.0 has also been used by the malware in one implementation. Through the C2 channel, operators can add and remove modules and exchange data with them, though Microsoft has not confirmed the specific functionality of the modules.
A NeedyMantis sample collected in October of 2025 contained a persistence module based on Windows services, however the persistence method employed by the newer analyzed sample has not been identified. The malware is more challenging to analyze through a single file or indicator due to its staged loading, misleading file names, encrypted archives, and modular C2 communication.
Detection points have been provided by Microsoft for hashes, file paths, the C2 hostname corp.tripswithengine[.]com, and the Firefox/21.0 user agent. As a result of the NeedyMantis campaign, security teams need to monitor suspicious loaders, C2 traffic, and unusual usage of legitimate software in order to recognize the risks posed by modular post-compromise malware.
.jpg)