Post

NeedyMantis Unpacking a Post-Compromise Malware Family

NeedyMantis Unpacking a Post-Compromise Malware Family

NeedyMantis: Unpacking a Post-Compromise Malware Family

Microsoft Threat Intelligence has identified NeedyMantis, a modular post-compromise malware family observed in a limited number of targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. 🚀

Based on observed activity, NeedyMantis is typically deployed after a threat actor has already established access to a target environment, indicating that the malware is used to maintain long-term access and support follow-on operations. NeedyMantis activity dates back to at least October 2025. We discovered the malware family while analyzing and pivoting from research and indicators of compromise associated with the DAEMON Tools supply chain compromise.

Observed activity involving NeedyMantis has thus far aligned with activity that Microsoft associates with threat actors operating from China. While NeedyMantis employs techniques commonly used by modern malware, its architecture combines multiple loaders, custom encrypted file archives, a custom executable file format, and modular components that enable operators to evade analysis and extend functionality through additional modules. 🔍

Microsoft has observed at least one threat actor using NeedyMantis malware: Storm-3069. Storm-3069 is Microsoft Threat Intelligence’s designator for activity associated with the DAEMON Tools supply chain compromise. While Microsoft assesses the activity originates from China, it has not attributed Storm-3069 to a Chinese nation-state actor. Microsoft has observed additional NeedyMantis activity beyond Storm-3069’s activity in the DAEMON Tools campaign, indicating that the malware might be used by more than one operator.

NeedyMantis has been observed in intrusions affecting telecommunications organizations, universities, intergovernmental organizations, medical nonprofits, and government contractors. Combined with the malware’s limited observed deployment and alignment with activity Microsoft associates with China-based threat actors, this victimology suggests NeedyMantis is deployed selectively rather than broadly.

Observed activity suggests that the malware is typically deployed after a threat actor has established access to a target environment. NeedyMantis is composed of multiple components written in C++ and x64 shellcode. The malware starts with a first-stage loader and a file archive. The loader and archive have been found packaged alongside legitimate software, with the first-stage loader—masquerading as a required DLL—being loaded through DLL sideloading.

Some of the open-source software abused by the malware include Poedit, curl, Vim, and TightVNC. Microsoft has also observed NeedyMantis masquerading as Microsoft Office, Broadcom, Intel, and NVIDIA DLL components. Examples of DLL path names used by the malware include %ProgramFiles%\Poedit\WinSparkle.dll, %ProgramData%\USOShared\libcurl.dll, %ProgramData%\VIM\vim64.dll, and %ProgramData%\office\dbghelp.dll.

In one observed incident, an operator used the Impacket toolkit during hands-on-keyboard activity to copy the legitimate software, malicious DLL, and file archive from a network share and execute it on a targeted device.

Read full article

This post is licensed under CC BY 4.0 by the author.