Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
On September 28, 2026, Microsoft Threat Intelligence published its analysis of NeedyMantis, a modular malware designed to indefinitely extend persistence in already-compromised networks. The framework has been observed in targeted intrusions against telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors, with activity tracing back to at least October 2025. The discovery illuminates an often-underestimated operational pattern: initial access is not the conclusion of an incident, but the starting point of a structural presence that can last months undetected.
- NeedyMantis is a modular post-compromise malware identified by Microsoft Threat Intelligence, active since at least October 2025 in targeted intrusions against strategic sectors
- The framework uses DLL sideloading on widely distributed legitimate programs — Poedit, curl, Vim, TightVNC — to load an obfuscated loader that extracts the malicious component from an encrypted archive
- Command-and-control communication occurs first via HTTPS on the domain corp.tripswithengine[.]com, then upgrades to WebSocket with a custom binary protocol supporting XOR, compression, and optional RC4
- Microsoft has observed NeedyMantis outside Storm-3069 activity, indicating multiple threat actors may share or reuse the same tool
The Execution Chain That Hides Shellcode Inside a PowerShell File
NeedyMantis architecture unfolds in a multi-stage sequence that exploits implicit trust in legitimate binaries. The distribution bundle comprises three elements: an authentic program, a malicious DLL with a filename matching the one loaded by the program, and an encrypted archive sharing the DLL's name. Microsoft has documented the use of Poedit, curl, Vim, and TightVNC as sideloading vectors; the DLL has also masqueraded as components of Microsoft Office, Broadcom, Intel, and NVIDIA.
In the sample analyzed in detail, dating to May 2026, the malicious file replaced WinSparkle.dll, Poedit's update component. The loader DLL dynamically resolves Windows functions through obfuscated stack strings, checks ProcessDebugFlags and ThreadHideFromDebugger flags to thwart sandbox analysis, then extracts from the encrypted archive — using variable offset parameters, XOR keys, and compression methods — a file named encryptbase64.ps1. This file, disguised as a PowerShell script, actually contains x64 shellcode that decodes the main component into a minimized custom executable format. Microsoft described the entire process as engineered to resist automated dissection and require prolonged manual analysis.
The core component then establishes connection with the C2 server. The first phase uses HTTPS to corp.tripswithengine[.]com on port 443, with user agent firefox/21.0 and URI /library/zip/. The channel subsequently upgrades to WebSocket, over which a proprietary binary protocol transits incorporating XOR encoding, compression, and optional RC4 encryption. Through this tunnel, operators can upload and download additional functional modules without replacing the main implant, reducing the need for new initial access and increasing resilience against signature-based detection.
Storm-3069, UNC6863, and the Limits of Attribution
Microsoft tracks the activity linked to the DAEMON Tools compromise campaign as Storm-3069, a group that uses NeedyMantis but is not the only one. The Redmond company explicitly stated it found no evidence that NeedyMantis was distributed through compromised DAEMON Tools installers: the malware's discovery followed indicators from Kaspersky's supply-chain attack investigation, but the two events were not directly linked.
Storm-3069 carries the "Storm" prefix, indicating a temporary name pending sufficient evidence for definitive attribution. Microsoft assesses the activity "appears to originate from China" but has not tied the group to a specific Chinese nation-state actor. Concurrently, Google Threat Intelligence Group tracks the actor behind the DAEMON Tools campaign as UNC6863, which Mandiant described in June 2026 as a "suspected China-nexus actor." It is unclear whether UNC6863 and Storm-3069 belong to the same group: infrastructure overlap has not been established to date.
More significant is the observation that Microsoft detected NeedyMantis outside Storm-3069 activity. This circumstance opens two non-mutually-exclusive readings: either the framework has been shared among distinct actors, or a common development infrastructure feeds multiple groups. In either case, the pattern is consistent with what has been observed in the APT ecosystem associated with Chinese interests, where tool reuse and modularity constitute established practice.
"Microsoft has also seen NeedyMantis outside Storm-3069's activity in the DAEMON Tools campaign, and it says more than one group may be using the malware."
Why Network Discovery Signals an Older and Deeper Intrusion
NeedyMantis is not an initial-access tool. It is, by Microsoft's definition, a "modular post-compromise malware framework," meaning its presence in a network indicates a prior compromise that has already cleared reconnaissance, lateral movement, and stabilization phases. In at least one documented intrusion, an operator already inside the network used Impacket to copy the bundle from a network share and execute it, confirming the malware is employed when the actor has already obtained credentials and internal foothold.
This post-compromise nature has direct investigative consequences. Detection of NeedyMantis must not trigger a localized, circumscribed response, but a full forensic investigation into lateral movement, credential theft, and additional persistence. Microsoft has not described how the latest malware version achieves persistence on the machine: documentation covers only a previous version, dating to October 2025, that included a Windows service-based persistence module. For the current variant, the survival mechanism across reboots remains unspecified.
A critical operational element emerges from the hunting queries Microsoft published: the lookback period is seven days. This time window is insufficient to detect events dating to October 2025 or May 2026, and risks losing the attacker's trail if applied without adaptations for historical searches over extended periods.
Immediate Actions
- Verify the presence of Microsoft-published IoCs — three specific SHA-256 hashes, the domain corp.tripswithengine[.]com:443, and the user agent firefox/21.0 — extending the search beyond the standard queries' seven-day lookback
- Analyze Poedit, curl, Vim, and TightVNC installations in sensitive networks to detect suspicious DLLs or anomalies in WinSparkle.dll files, comparing hashes against those documented
- Inspect HTTPS and WebSocket traffic to endpoints with URI pattern /library/zip/ and legitimate-sounding domain names, given NeedyMantis's ability to upgrade its communication protocol
- Launch a full forensic investigation into lateral movement and persistence upon NeedyMantis detection, treating the malware as an indicator of prior compromise rather than an isolated event
Open Questions
Microsoft has not confirmed the specific capabilities of additional modules downloadable via the WebSocket connection. The exact number of victims and the full scope of compromised entities have not been made public. It also remains undetermined whether the activity is actually Chinese state-sponsored or merely aligned with Chinese interests: the attributional distinction, often glossed over in press releases, is relevant for calibrating geopolitical response and sanctions. Finally, it is unclear whether NeedyMantis remains active at the time of the analysis publication, though the framework's modular nature suggests a prolonged lifecycle.
The emergence of NeedyMantis confirms a technical and strategic trend: the separation between initial access and presence maintenance. Threat actors increasingly invest resources in the post-compromise phase, developing resilient, reusable, and difficult-to-attribute tools. For defenders, this means response quality is measured not by the speed of eradicating the first sample, but by the depth of investigation it demands.
Sources
- https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html
- https://firsthackersnews.com/needymantis-malware-network-access/
- https://www.cryptika.com/microsoft-finds-new-malware-used-by-hackers-to-maintain-secret-access-inside-target-networks/
- https://blog.netmanageit.com/hackers-use-needymantis-to-maintain-long-term-access-in-breached-networks/
- https://security.googlecloudcommunity.com/security-validation-5/validation-content-update-june-24-2026-7779
- https://thehackernews.uk/enterprise-ai-security-a
- https://thehackernews.com/2026/05/daemon-tools-supply-chain-attack.html
- https://thehackernews.uk/trust-world-update-d
- https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html?ref=blog.netmanageit.com
Information verified against cited sources and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.