Microsoft Tracks NeedyMantis Malware Targeting Telecoms and Government Contractors
Microsoft details NeedyMantis, a modular post-compromise malware framework targeting telecoms, government contractors and intergovernmental organizations, linked to China-origin cluster Storm-3069.
Microsoft Threat Intelligence identified NeedyMantis, a C++ post-compromise framework with DLL sideloading via legitimate apps like Poedit, curl, Vim and TightVNC, active since at least October 2025. The malware was found while investigating the DAEMON Tools supply-chain compromise previously reported by Kaspersky, and Microsoft linked at least one user to Storm-3069, a China-origin activity cluster. C2 starts over HTTPS then switches to WebSockets, with the analyzed configuration using corp.tripswithengine[.]com on port 443 and URI /library/zip/. Victims span telecommunications, government contractors, universities, medical nonprofits and intergovernmental organizations.
- Modular post-compromise framework active since October 2025, linked to Storm-3069 (China-origin)
- Uses DLL sideloading with legitimate apps and masquerades as Microsoft, Broadcom, Intel, NVIDIA DLLs
- C2 moves from HTTPS to WebSockets; hardcoded Firefox/21.0 user-agent aids threat hunting
- Found during investigation of the DAEMON Tools supply-chain compromise reported by Kaspersky
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | tripswithengine.com | g to WebSockets. The analyzed configuration referenced corp.tripswithengine[.]com on port 443 and used the URI /library/zip/. Its communica |
| sha256 | 9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef | loader masquerading as WinSparkle.dll 2026-05-21 2026-05-21 9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef SHA-256 Custom encrypted NeedyMantis file archive named Win |
| sha256 | c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77 | yMantis file archive named WinSparkle 2026-05-23 2026-05-23 c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77 SHA-256 Older NeedyMantis custom archive named libcurl 2025 |
| sha256 | e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e | tables. IoC Indicator Type Description First Seen Last Seen e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e SHA-256 NeedyMantis first-stage DLL loader masquerading as |
Full article787 words · extracted from gbhackers.com · click to collapse
Microsoft Threat Intelligence has discovered NeedyMantis, a modular post-compromise malware framework that targets specific industries, including telecommunications firms, government contractors, universities, medical nonprofits, and intergovernmental organizations.
Unlike typical malware that serves as an initial access point, NeedyMantis is designed to maintain an attacker’s access and support follow-on operations after an initial breach.
NeedyMantis activity has been traced back to at least October 2025. Microsoft identified the malware while investigating indicators related to the DAEMON Tools supply-chain compromise, which Kaspersky previously reported.
The company has linked at least one user of this malware to Storm-3069, an activity cluster that Microsoft assesses as originating from China; however, it has not attributed the group to a specific Chinese nation-state actor.
Microsoft Tracks NeedyMantis Malware
According to Microsoft, NeedyMantis is typically introduced after attackers have established a foothold in a victim’s environment. In one incident, operators utilized the Impacket toolkit for hands-on-keyboard activity, copying legitimate software, a malicious DLL, and an accompanying archive from a network share before executing them on a target endpoint.
The malware exploits DLL sideloading by pairing a malicious first-stage loader with legitimate applications such as Poedit, curl, Vim, and TightVNC.
It also disguises itself as DLLs associated with reputable companies like Microsoft Office, Broadcom, Intel, and NVIDIA. Observed file names include WinSparkle.dll, libcurl.dll, vim64.dll, dbghelp.dll, jli.dll, and nvml.dll.

In one analyzed case, the malware used a malicious WinSparkle.dll to impersonate the WinSparkle update component of the Poedit translation application. When the trusted executable runs, it sideloads the malicious DLL, which then extracts and executes the malware’s next stage.
NeedyMantis consists of C++ components, x64 shellcode, encrypted archives, and a custom minimized executable format. Its first-stage loader employs obfuscated stack strings, dynamically resolves Windows APIs, and includes anti-debugging checks based on ProcessDebugFlags and ThreadHideFromDebugger.
The loader decrypts and decompresses a custom archive, with its structure and XOR keys varying among samples.
In Microsoft’s analysis, one archive contained legitimate 7-Zip and Sysinternals components alongside malicious files disguised as Windows libraries, including dnsapi.dll, which stores configuration data, and ws2_32.dll, which facilitates WebSockets-based command-and-control communications.
A second-stage payload named encryptbase64.ps1 was not actually a PowerShell script; it contained x64 shellcode that decoded and loaded NeedyMantis’s primary component.
This main payload manages command-and-control (C2) traffic and supports the loading, unloading, and interaction with additional modules, allowing operators to expand functionality as needed. The specific capabilities of these modules have not yet been confirmed.
NeedyMantis initially communicates over HTTPS before switching to WebSockets. The analyzed configuration referenced corp.tripswithengine[.]com on port 443 and used the URI /library/zip/. Its communication component also included a hard-coded user agent string for Firefox/21.0, which serves as a useful artifact for network threat hunting.
Microsoft recommends that defenders investigate outbound traffic to the identified domain, enable cloud-delivered protection and endpoint detection and response (EDR) in block mode, activate network protection, and apply attack surface reduction rules that block suspicious or obfuscated scripts and untrusted executables.
IoC
| Indicator | Type | Description | First Seen | Last Seen |
|---|---|---|---|---|
e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e | SHA-256 | NeedyMantis first-stage DLL loader masquerading as WinSparkle.dll | 2026-05-21 | 2026-05-21 |
9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef | SHA-256 | Custom encrypted NeedyMantis file archive named WinSparkle | 2026-05-23 | 2026-05-23 |
c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77 | SHA-256 | Older NeedyMantis custom archive named libcurl | 2025-10-03 | 2025-10-03 |
corp.tripswithengine[.]com | Domain / C2 host | NeedyMantis command-and-control infrastructure, configured for HTTPS port 443 | N/A | N/A |
/library/zip/ | URI path | C2 URI identified in the analyzed NeedyMantis configuration | N/A | N/A |
Firefox/21.0 | User-Agent | Hard-coded user-agent used by the NeedyMantis WebSockets communications DLL | N/A | N/A |
WinSparkle.dll | Filename | Malicious first-stage loader impersonating the WinSparkle update component | N/A | N/A |
WinSparkle | Filename | Encrypted custom archive deployed alongside the malicious WinSparkle.dll loader | N/A | N/A |
libcurl.dll | Filename | DLL name used by NeedyMantis to masquerade as a legitimate curl component | N/A | N/A |
vim64.dll | Filename | DLL filename used in NeedyMantis DLL sideloading chains involving Vim or TightVNC directories | N/A | N/A |
dbghelp.dll | Filename | Masqueraded DLL observed in fake Office and Broadcom application paths | N/A | N/A |
jli.dll | Filename | Masqueraded DLL observed in a fake Intel application path | N/A | N/A |
nvml.dll | Filename | Masqueraded DLL observed in fake NVIDIA-related application paths | N/A | N/A |
encryptbase64.ps1 | Filename | Second-stage x64 shellcode loader disguised as a PowerShell script | N/A | N/A |
dnsapi.dll | Filename | Spoofed Windows DLL filename used to store NeedyMantis configuration data | N/A | N/A |
ws2_32.dll | Filename | Spoofed Windows networking DLL filename used for WebSockets-based C2 communications | N/A | N/A |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.