Microsoft Details China-Linked 'NeedyMantis' Post-Compromise Malware Used for Long-Term Access in Targeted Intrusions
Microsoft Threat Intelligence disclosed NeedyMantis on September 28, 2026, a previously unseen modular post-compromise framework written in C++ and x64 shellcode, active since at least October 2025 against telecoms, universities, medical nonprofits,…
Microsoft Threat Intelligence disclosed NeedyMantis on September 28, 2026, a previously unidentified modular post-compromise malware family written in C++ and x64 shellcode, seen since at least October 2025 in a limited number of targeted intrusions against telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Deployed only after access is obtained — operators copy the bundle with Impacket from a network share and run it from there via hands-on-keyboard activity — the bundle consists of a legitimate program, a sideloaded DLL, and an encrypted archive, abusing DLL sideloading of Poedit, curl, Vim, and TightVNC alongside DLLs masquerading as Microsoft, Broadcom, Intel, and NVIDIA components; an older build persisted via a Windows service module. After installation, a second-stage loader contacts command-and-control, with the final stage providing command-and-control, data theft, and additional payloads. The implant beacons to corp.tripswithengine[.]com over HTTPS before switching to WebSockets with custom encoding; GBHackers specifies port 443 and URI /library/zip/ with a hardcoded Firefox/21.0 user-agent, and SecurityWeek reports the WebSocket channel exposes ten control functions, with module capabilities remaining unconfirmed. One known operator is Storm-3069, which Microsoft assesses has a China nexus but has not attributed to a nation-state or to a single operator; other outlets describe the cluster as China-based or China-origin, SecurityWeek says possibly other Chinese actors have also used the malware, and Dark Reading describes a China-based threat actor deploying the previously unseen framework. Microsoft found NeedyMantis while investigating the DAEMON Tools supply-chain compromise previously reported by Kaspersky and tracked by Google as UNC6863, and states the malware was not delivered through the poisoned installers — Infosecurity likewise reports no evidence of distribution via that compromise — whereas SecurityWeek dates the attack to May 2026, reports that poisoned official-site installers infected thousands of computers with a backdoor deployed on roughly a dozen government, scientific, manufacturing, and retail systems in Belarus, Russia, and Thailand, and describes Storm-3069 as using NeedyMantis after that attack. Published indicators include three SHA-256 hashes and the Microsoft Defender detection TrojanDropper:Win64/NeedyMantis; defenders are advised to match…
- NeedyMantis is a modular post-compromise malware family written in C++ and x64 shellcode, disclosed by Microsoft Threat Intelligence on September 28, 2026, and observed since at least October 2025.
- Victims span telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors in a limited number of targeted intrusions.
- Deployment occurs after initial access via Impacket copies run from a network share and hands-on-keyboard activity; the bundle combines a legitimate program, a sideloaded DLL, and an encrypted archive.
- DLL sideloading abuses legitimate software (Poedit, curl, Vim, TightVNC) and masquerades as Microsoft, Broadcom, Intel, and NVIDIA DLLs; an older build persisted through a Windows service module.
- A second-stage loader contacts command-and-control, with the final stage providing command-and-control, data exfiltration, and additional payloads; SecurityWeek reports module capabilities remain unconfirmed.
- C2 beacons to corp.tripswithengine[.]com over HTTPS before switching to WebSockets with custom encoding; the analyzed configuration uses port 443 and URI /library/zip/ with a hardcoded Firefox/21.0 user-agent.
- SecurityWeek reports the WebSockets command-and-control channel exposes ten control functions.
- One known operator is Storm-3069, which Microsoft assesses has a China nexus without attributing it to a nation-state or a single operator; other outlets describe the cluster as China-based or China-origin, and SecurityWeek says possibly…
Coverage timelineoldest first · each row is one article
- · 1d agoNeedyMantis: Unpacking a post-compromise malware family used in targeted operations
Microsoft Security Blog· 66
Microsoft details NeedyMantis, modular post-compromise malware used in targeted intrusions linked to China-based operators.
- · 1d agoMicrosoft Finds New Malware Used by Hackers to Maintain Secret Access Inside Target Networks
Cyber Security News· 76
Microsoft uncovers NeedyMantis, a modular backdoor keeping covert access in targeted telecom, university, and government networks.
- · 1d agoHackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
The Hacker News· 73