In a technical analysis published September 28, 2026, Microsoft Threat Intelligence described NeedyMantis as modular malware typically deployed after an attacker has gained access to an organization’s environment. Microsoft says activity dates back at least to October 2025 and reports targeted operations involving several types of organizations. Its analysis traces how one sample used staged loaders and moved its command-and-control traffic from HTTPS to WebSockets.

What NeedyMantis does after access

NeedyMantis is post-compromise malware: Microsoft says operators generally deploy it after establishing access to a target environment. The malware’s modular design lets its main component handle modules, including commands to load or unload them and dispatch data to them. Microsoft says some observed activity dates back to at least October 2025.

Microsoft reports affected organizations in telecommunications, higher education, medical nonprofits, intergovernmental organizations and government contracting. These are sectors represented in the activity Microsoft observed.

How the analyzed NeedyMantis sample works

Microsoft details NeedyMantis malware’s post-compromise operation

In the analyzed sample, a first-stage loader extracted a second loader from a custom archive. The second-stage loader contained x64 shellcode despite its .ps1 filename, then decoded the malware’s main component. The archive was encrypted and compressed, and its format used XOR decoding and RtlDecompressBuffer.

The main component handled communications with a command-and-control (C2) server—the infrastructure an operator uses to communicate with malware—and managed downloaded modules. In the analyzed sample, communications began with an HTTPS GET request and then switched to WebSockets. Microsoft says the capabilities of the downloaded modules remain unconfirmed.

How the malware was deployed and disguised

In one reported incident, an operator who already had access to the network used Impacket to copy legitimate software, a malicious DLL and an archive from a network share, then ran them on a target device. The method used to gain initial access can vary.

In the analyzed sample, the malicious DLL spoofed WinSparkle, an update component associated with the translation application Poedit. It was loaded through DLL sideloading, a technique in which a malicious DLL is loaded in place of a legitimate component expected by a program. Microsoft also lists Poedit, curl, Vim and TightVNC among legitimate software associated with observed packaging, and says the malware masqueraded as DLL components associated with Microsoft Office, Broadcom, Intel and NVIDIA.

What Microsoft says about attribution

Microsoft identifies Storm-3069 as one observed user of NeedyMantis and says the activity aligns with activity it associates with China-based threat actors. It has not attributed Storm-3069 to a Chinese nation-state actor or determined whether one operator accounts for all observed NeedyMantis activity.

Microsoft encountered NeedyMantis while following indicators associated with the DAEMON Tools supply-chain compromise investigation. That connection describes how the analysis developed; Microsoft has not observed NeedyMantis itself being distributed through a supply-chain compromise.

Indicators and defensive guidance

Microsoft published indicators for the analyzed samples, including these SHA-256 hashes:

  • e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e — the WinSparkle.dll loader, first and last seen May 21, 2026.
  • 9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef — the WinSparkle archive, first and last seen May 23, 2026.
  • c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77 — an older libcurl archive, first and last seen October 3, 2025.

Other reported indicators include the C2 hostname corp.tripswithengine[.]com and the communications DLL’s hard-coded user-agent, firefox/21.0. Microsoft lists the Defender detections TrojanDropper:Win64/NeedyMantis and Behavior:Win64/NeedyMantis.

Microsoft recommends monitoring outbound traffic to the reported C2 hostname, enabling cloud-delivered protection and block at first sight, running Endpoint Detection and Response in block mode, enabling network protection and automatic attack disruption, and considering attack-surface-reduction rules for potentially obfuscated scripts and executable files.

Microsoft’s Defender XDR and Sentinel hunting queries use a rolling seven-day lookback. Run unchanged, they do not search back to the older first-seen dates in the indicator list.