Microsoft has identified a new malware framework called NeedyMantis, designed to help attackers maintain access to networks that have already been compromised.
The malware has been seen in a small number of targeted attacks involving telecommunications companies, universities, medical nonprofits, government contractors, and intergovernmental organizations.
The activity goes back to at least October 2025, suggesting that the attackers have been using NeedyMantis for long-term access rather than widespread attacks.
How NeedyMantis Gets Into a Network
Microsoft discovered NeedyMantis while investigating activity connected to the DAEMON Tools supply-chain compromise, tracked as Storm-3069.
However, Microsoft has not found evidence that NeedyMantis was delivered through the compromised DAEMON Tools software. Instead, the malware appears to be installed after attackers have already gained access to a target.
In one case, attackers used the Impacket toolkit to move legitimate software, a malicious DLL, and an encrypted archive from a network share to a selected computer.
The malware uses DLL sideloading, where a legitimate application loads a malicious library disguised as a required file.
Attackers have used software packages involving Poedit, curl, Vim, and TightVNC while giving malicious files names that resemble Microsoft, Broadcom, Intel, and NVIDIA libraries.
The first-stage loader then extracts another payload from a specially created archive. Different samples use changing filenames, offsets, compression methods, and XOR keys, making the malware harder to detect and analyze.
Malware Uses Multiple Layers to Hide
In one sample analyzed by Microsoft, a malicious WinSparkle.dll replaced the legitimate update component used by Poedit.
The loader also hides important API names and uses several checks designed to make analysis more difficult.
It eventually extracts a file named encryptbase64.ps1. Despite the .ps1 extension, the file actually contains x64 shellcode that decodes and loads the main NeedyMantis component.
Once running, NeedyMantis manages communication with the attackers and can download additional modules.
The malware uses HTTPS before switching to WebSockets for further communication. Its traffic can include compression, XOR encoding, and optional RC4 encryption.
The initial connection can send information about the infected system, including:
- Computer name
- Username
- Running processes
- Parent process
- Installed files
- Process information
The malware can also receive commands to load or remove modules, send information, and maintain communication with the attackers.
Microsoft has not confirmed what all of the additional modules can do. However, the modular design allows attackers to add new capabilities without replacing the main malware.
What Security Teams Should Look For
Because NeedyMantis appears to be used after initial compromise, finding it should lead to a wider investigation.
Security teams should check for:
- Suspicious DLL sideloading
- Unexpected Impacket activity
- Obfuscated scripts and decoding activity
- Unknown DLLs beside legitimate applications
- Connections to
corp.tripswithengine[.]com - Signs of credential theft or lateral movement
- Other persistence mechanisms
Microsoft also recommends using cloud-delivered protection, network protection, EDR, attack-surface-reduction rules, and protections against untrusted executables and obfuscated scripts.
The main concern with NeedyMantis is its ability to provide attackers with a flexible and persistent foothold after a network has already been breached.