Full Report
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use goes back to at least
Analysis Summary
# Tool/Technique: NeedyMantis
## Overview
NeedyMantis is a post-compromise malware family utilized by threat actors to maintain long-term, persistent access to networks that have already been breached. It is deployed in highly targeted operations primarily focusing on telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors.
## Technical Details
- Type: Malware family
- Platform: Windows
- Capabilities: DLL sideloading, encrypted payload execution, modular command-and-control (C2) communication, and dynamic plugin execution.
- First Seen: October 2025
## MITRE ATT&CK Mapping
- [TA0003 - Persistence]
- [T1574.002 - Hijack Execution Flow: DLL Side-Loading]
- [T1543.003 - Create or Modify System Process: Windows Service] (Observed in older variants)
- [TA0008 - Lateral Movement]
- [T1021.002 - Remote Services: SMB/Windows Admin Shares]
- [TA0011 - Command and Control]
- [T1071.001 - Application Layer Protocol: Web Protocols] (HTTPS and WebSockets)
## Functionality
### Core Capabilities
- **DLL Sideloading:** NeedyMantis is deployed as a three-part bundle containing a legitimate executable, a malicious DLL masquerading as a dependency, and an encrypted archive. When the legitimate application runs, it inadvertently loads the malicious DLL.
- **Multi-Stage Unpacking:** Once executed, the malicious loader DLL extracts the next stage from the encrypted archive, which decodes and executes the core NeedyMantis malware component in memory.
- **C2 Communication:** The core component initiates an initial connection over HTTPS and seamlessly transitions to a persistent WebSocket connection to communicate with operator-controlled infrastructure.
### Advanced Features
- **Modular Architecture:** The malware features an extensible framework allowing operators to dynamically load and unload additional functional modules and pipe data through them over the active WebSocket channel.
- **Masquerading:** It heavily leverages the identities of trusted software vendors. Legitimate binaries exploited for sideloading include Poedit, curl, Vim, and TightVNC. The malicious DLL components also masquerade as legitimate files belonging to Microsoft Office, Broadcom, Intel, and NVIDIA.
## Indicators of Compromise
- **File Hashes:**
- SHA-256: `e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e` (First-stage loader mimicking `WinSparkle.dll`)
- **File Names:** `WinSparkle.dll` (associated with the Poedit update component; other filenames mimic Microsoft, Intel, Broadcom, and NVIDIA DLLs).
- **Registry Keys:** *None specified in the source text.*
- **Network Indicators:** *None specified in the source text.*
- **Behavioral Indicators:** Execution of legitimate applications (e.g., Poedit, curl, Vim, TightVNC) from unusual or non-standard directory paths accompanied by network connections upgrading to WebSockets. Lateral movement involving the Impacket toolkit copying files via administrative network shares.
## Associated Threat Actors
- **Storm-3069** (Microsoft tracking designation)
- **UNC6863** (Google Threat Intelligence / Mandiant tracking designation)
- **China-nexus Threat Actors** (Assessed based on targeting profiles and Chinese-language components identified in related campaign code).
## Detection Methods
- **Behavioral Detection:** Monitor for unexpected DLL loads by common legitimate utilities (such as curl, Vim, and TightVNC) located outside of their typical installation directories. Track outbound network connections originating from these utilities that transition from standard HTTPS to WebSockets.
- **Lateral Movement Monitoring:** Implement detection rules for the use of the Impacket toolkit, specifically focusing on unexpected remote file transfers and service creations over SMB/Windows admin shares.
## Mitigation Strategies
- **Application Whitelisting / Control:** Restrict execution paths for known utilities (like curl, Vim, and TightVNC) to secure, administrative-only directories to mitigate arbitrary folder deployment and subsequent sideloading.
- **Network Segmentation & Share Restrictions:** Limit the use of administrative shares (e.g., `ADMIN$`, `C$`) and restrict lateral movement tools by enforcing strict network segmentation and monitoring internal SMB traffic.
- **Endpoint Detection and Response (EDR):** Deploy EDR policies configured to detect signatureless, multi-stage file execution originating from encrypted blobs/archives.
## Related Tools/Techniques
- **Impacket Toolkit:** Used by threat operators inside the network to copy and execute the NeedyMantis bundle across network shares.
- **DAEMON Tools Supply Chain Attack:** The broader campaign context wherein indicators for NeedyMantis were discovered following a compromise of official DAEMON Tools Lite installers.