Full Report
Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components to maintain long-term access and support follow-on operations. The post NeedyMantis: Unpacking a post-compromise malware family used in targeted operations appeared first on Microsoft Security Blog.
Analysis Summary
# Tool/Technique: NeedyMantis
## Overview
NeedyMantis is a sophisticated, modular post-compromise malware framework designed for long-term persistence and follow-on operations. It is characterized by its use of multi-stage custom loaders, encrypted file archives, and a custom executable format. The framework is typically deployed after initial access has been established to facilitate targeted intrusions.
## Technical Details
- **Type:** Malware family / Post-compromise framework
- **Platform:** Windows
- **Capabilities:** Persistence, modular extension via plugins, encrypted communication, custom archive handling, and evasion of traditional analysis.
- **First Seen:** October 2025
## MITRE ATT&CK Mapping
- **[TA0003 - Persistence]**
- [T1574.002 - Hijack Execution Flow: DLL Side-Loading]
- **[TA0005 - Defense Evasion]**
- [T1140 - Deobfuscate/Decode Files or Information]
- [T1027 - Obfuscated Files or Information]
- **[TA0011 - Command and Control]**
- [T1071.001 - Application Layer Protocol: Web Protocols]
- [T1573.001 - Encrypted Channel: Symmetric Cryptography]
## Functionality
### Core Capabilities
- **Modular Architecture:** Utilizes a core engine that can load additional modules to expand functionality based on operator needs.
- **Custom Loading Mechanism:** Employs multi-stage loaders (often masquerading as legitimate DLLs like `WinSparkle.dll` or `libcurl.dll`) to decrypt and execute the primary payload.
- **Custom File Archives:** Uses a proprietary encrypted archive format to store components, hindering automated sandbox analysis and static detection.
- **Persistence:** Designed to maintain a low-profile, long-term presence within highly sensitive environments.
### Advanced Features
- **Custom Executable Format:** Instead of standard PEs, the framework has been observed using a custom format for its internal modules to bypass security tooling.
- **Supply Chain Integration:** Linked to the DAEMON Tools supply chain compromise (Storm-3069), where it was distributed via compromised software updates.
## Indicators of Compromise
- **File Hashes:**
- `e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e` (First-stage loader - WinSparkle.dll)
- `9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef` (Custom file archive)
- `c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77` (Custom file archive - libcurl)
- **File Names:**
- `WinSparkle.dll`
- `libcurl.dll`
- **Network Indicators:**
- `corp.tripswithengine[.]com` (C2 Domain)
- **Behavioral Indicators:**
- Network traffic utilizing a hard-coded User-Agent: `Firefox/21.0`.
- Side-loading of DLLs into legitimate application processes.
## Associated Threat Actors
- **Storm-3069:** A threat group (assessed to operate from China) associated with the DAEMON Tools supply chain compromise.
## Detection Methods
- **Signature-based detection:** Microsoft Defender tracks these components under specific NeedyMantis signatures.
- **Behavioral detection:** Monitoring for unusual DLL loading events in common software directories and identifying the specific `Firefox/21.0` User-Agent in non-browser process traffic.
- **Hunting:** Use KQL queries to identify connectivity to known C2 domains or suspicious User-Agent strings in `CommonSecurityLog`.
## Mitigation Strategies
- **DLL Sideloading Prevention:** Implement strict AppLocker or Windows Defender Application Control (WDAC) policies to prevent unauthorized DLLs from loading.
- **Supply Chain Security:** Validate the integrity of software updates and monitor for anomalies in third-party software behavior.
- **Network Segmentation:** Restrict outbound traffic to known-good domains and monitor for unusual C2 patterns.
- **Endpoint Monitoring:** Deploy EDR solutions to detect suspicious process injections and the creation of non-standard file formats in system directories.
## Related Tools/Techniques
- **DAEMON Tools Backdoor:** The initial infection vector associated with this framework.
- **WinSparkle/Poedit:** Legitimate frameworks/tools whose names are often spoofed by NeedyMantis loaders.