NeedyMantis Gives Intruders a Modular Backdoor After the Initial Breach

Microsoft details NeedyMantis, a modular post-breach backdoor using DLL sideloading and encrypted WebSocket C2 to retain control in targeted intrusions.

NeedyMantis Gives Intruders a Modular Backdoor After the Initial Breach
APT

Illustrative image generated with AI

Malware built to extend an existing compromise

Microsoft has detailed a malware family called NeedyMantis, used by attackers to retain control of systems after gaining access through other means. The company has observed the malware in targeted intrusions dating back to at least October 2025.

The affected organizations include telecommunications providers, universities, medical nonprofits, intergovernmental bodies, and government contractors. Only a limited number of victims have been identified, suggesting selective deployment rather than broad, opportunistic distribution.

NeedyMantis is not an initial-access exploit. In the incidents examined, operators were already inside the victim’s network before placing and executing the malware. The entry method may therefore vary from one intrusion to another, and Microsoft has not identified a single technique responsible for all infections.

There is no CVE or CVSS score associated with NeedyMantis. No vulnerable software build is identified because the threat is a post-compromise malware tool, not a disclosed product flaw.

Once active, NeedyMantis establishes an encrypted command channel and gives its operators a mechanism for adding or removing modules. Microsoft has not determined what those additional components do, leaving the malware’s complete operational capabilities unknown.

A three-file chain abuses DLL search behavior

The NeedyMantis package seen by Microsoft contains three elements:

  1. A legitimate executable.
  2. A malicious DLL named like a library expected by that executable.
  3. An encrypted archive carrying the next stage.

When the trusted program starts, it loads the attacker-controlled library through DLL sideloading. This technique takes advantage of how an application searches for required DLLs, allowing malicious code to run under the context of an otherwise legitimate process.

The first-stage DLL extracts and launches content from the encrypted archive. That stage then decodes NeedyMantis’ principal component, which handles communications with the command-and-control infrastructure.

Attackers have paired the package with legitimate programs including Poedit, curl, Vim, and TightVNC. Malicious libraries have also impersonated DLLs associated with Microsoft Office, Broadcom, Intel, and NVIDIA.

In the sample examined most closely, the attackers replaced WinSparkle.dll, the update component used by Poedit. That filename requires careful interpretation during incident response because a legitimate Poedit installation can also contain a genuine file at the same location.

One documented operator used the Impacket toolkit to copy the three-part bundle from a network share and launch it on a target computer. This activity shows lateral deployment after compromise, but it does not explain how the attackers first entered the environment.

HTTPS and WebSocket traffic support modular operations

After decoding, the main NeedyMantis component contacts its command-and-control server over HTTPS. It subsequently upgrades or changes the session to a WebSocket connection, creating a persistent bidirectional channel between the compromised host and the operator.

Through this connection, attackers can load modules, unload them, and route data to those components. The design lets operators change functionality without replacing the central malware component.

The purpose of the observed modules remains unconfirmed. Available analysis does not establish whether they support credential theft, network discovery, data collection, lateral movement, or other post-compromise tasks.

A NeedyMantis version observed on October 3, 2025 included a persistence module that registered Windows services. The persistence method used by the newer analyzed version has not been disclosed.

The malware’s communications DLL uses a hard-coded firefox/21.0 user-agent string. That value, combined with the destination domain and WebSocket behavior, may help defenders separate suspicious sessions from ordinary browser traffic.

DAEMON Tools investigation exposed a broader connection

Microsoft encountered NeedyMantis while investigating indicators connected to the compromise of official DAEMON Tools Lite installers. Malicious code reportedly appeared in signed installers beginning April 8, 2026, and the developer replaced those files with a clean release on May 5, 2026.

Microsoft tracks activity associated with that campaign as Storm-3069. However, it has not observed NeedyMantis being delivered by the compromised DAEMON Tools installers.

The distinction matters. Storm-3069 is one actor known to use NeedyMantis, but Microsoft has also found the malware outside that group’s activity in the DAEMON Tools operation. Multiple groups may therefore have access to the same malware family.

Microsoft uses “Storm” designations provisionally when an actor’s identity or origin remains unresolved. It assesses that Storm-3069 activity appears to originate in China, but has not attributed the group to the Chinese government.

The broader NeedyMantis activity is also described as consistent with China-linked groups, based on the small target set and victim selection aligned with Chinese interests. That assessment does not prove that every NeedyMantis deployment has the same operator.

Kaspersky found Chinese-language text in malware connected to the DAEMON Tools incident but did not name a specific group. Google Threat Intelligence Group tracks the campaign actor as UNC6863, while Mandiant has characterized UNC6863 as a suspected China-nexus actor. It remains unknown whether UNC6863 and Storm-3069 represent the same organization.

Hashes, network artifacts, and suspicious paths

Microsoft provided the following file indicators:

  • e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e
    First-stage WinSparkle.dll loader, first seen May 21, 2026.

  • 9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef
    Encrypted archive named WinSparkle, first seen May 23, 2026.

  • c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77
    Older encrypted archive named libcurl, first seen October 3, 2025.

The identified command-and-control domain is:

corp.tripswithengine[.]com

Communications use port 443, with the hard-coded user agent:

firefox/21.0

Reported malicious DLL locations include:

%ProgramFiles%\Poedit\WinSparkle.dll
%ProgramData%\USOShared\libcurl.dll
%ProgramData%\VIM\vim64.dll
%ProgramData%\TightVNC\VIM\vim64.dll
%ProgramData%\office\dbghelp.dll
%ProgramData%\broadcom\dbghelp.dll
%ProgramData%\Intel\jli.dll
%ProgramFiles%\modifiable\nvml.dll
%ProgramData%\ics\nvml.dll

A path match alone is not always conclusive. In particular, WinSparkle.dll can be a legitimate Poedit component, so investigators should calculate its SHA-256 hash and compare it with the known malicious value.

Microsoft Defender Antivirus reportedly identifies the threat as TrojanDropper:Win64/NeedyMantis and Behavior:Win64/NeedyMantis.

Defensive actions and investigation limits

Organizations should search historical DNS, proxy, firewall, and endpoint telemetry for the C2 domain, port 443 connections, and the unusual firefox/21.0 user agent. File-system searches should cover the listed paths, followed by hash validation and signature checks.

Microsoft has released hunting queries for Defender XDR and Microsoft Sentinel. Those queries examine only the previous seven days in their published form. Investigators seeking activity from October 2025 or May 2026 must expand the time range where retained telemetry permits it.

Recommended Defender controls include cloud-delivered protection, Block at first sight, EDR in block mode, network protection, and automatic attack disruption. Microsoft also recommended two attack surface reduction rules, although their names and configuration details have not been disclosed in the available reporting.

For the separate DAEMON Tools incident, anyone who downloaded or installed free DAEMON Tools Lite 12.5.1 during the affected period was advised to uninstall it, perform a full system scan, and install version 12.6 from the official website. That remediation addresses the compromised installer campaign, not a confirmed NeedyMantis delivery path.

The central investigation gap remains the same: NeedyMantis confirms continued attacker access, but does not reveal the original breach route. A positive detection should therefore trigger broader incident response, including credential review, lateral-movement analysis, network-share auditing, and a search for earlier intrusion activity.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →