{"id":61429,"date":"2026-09-28T15:00:00","date_gmt":"2026-09-28T15:00:00","guid":{"rendered":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/?p=149653"},"modified":"2026-09-28T15:00:00","modified_gmt":"2026-09-28T15:00:00","slug":"needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\/","title":{"rendered":"NeedyMantis: Unpacking a post-compromise malware family used in targeted operations"},"content":{"rendered":"<aside class=\"table-of-contents-block accordion wp-block-bloginabox-theme-table-of-contents\" id=\"accordion-c5ebffce-c72c-48f9-95d5-1751e0f42f1f\" data-bi-an=\"table-of-contents\"> <button class=\"btn btn-collapse\" type=\"button\" aria-expanded=\"true\" aria-controls=\"accordion-collapse-c5ebffce-c72c-48f9-95d5-1751e0f42f1f\"> <span class=\"table-of-contents-block__label\">In this article<\/span> <span class=\"table-of-contents-block__current\" aria-hidden=\"true\"><\/span> <svg class=\"table-of-contents-block__arrow\" aria-label=\"Toggle arrow\" width=\"18\" height=\"11\" viewBox=\"0 0 18 11\" fill=\"none\"> <path d=\"M15.7761 11L18 8.82043L9 0L0 8.82043L2.22394 11L9 4.35913L15.7761 11Z\" fill=\"currentColor\" \/> <\/svg> <\/button> <span class=\"table-of-contents-block__progress-bar\"><\/span><br \/>\n<\/aside>\n<p class=\"wp-block-paragraph\">Microsoft Threat Intelligence has identified NeedyMantis, a modular post-compromise malware family observed in a limited number of targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Based on observed activity, NeedyMantis is typically deployed after a threat actor has already established access to a target environment, indicating that the malware is used to maintain long-term access and support follow-on operations.<\/p>\n<p class=\"wp-block-paragraph\">NeedyMantis activity dates back to at least October 2025. We discovered the malware family while analyzing and pivoting from research and indicators of compromise associated with the DAEMON Tools supply chain compromise, which <a href=\"https:\/\/securelist.com\/tr\/daemon-tools-backdoor\/119654\/\">Kaspersky previously reported<\/a> on as part of its investigation into the campaign. Observed activity involving NeedyMantis has thus far aligned with activity that Microsoft associates with threat actors operating from China, although Microsoft has not determined whether all observed activity is attributable to the same operator.<\/p>\n<p class=\"wp-block-paragraph\">While NeedyMantis employs techniques commonly used by modern malware, its architecture combines multiple loaders, custom encrypted file archives, a custom executable file format, and modular components that enable operators to evade analysis and extend functionality through additional modules. These characteristics, combined with its use in targeted intrusions, make NeedyMantis a useful case study for understanding how threat actors establish and maintain long-term access within victim environments.<\/p>\n<p class=\"wp-block-paragraph\">In this blog, we analyze the NeedyMantis malware framework. We examine its packaging and deployment, custom archive format, loader architecture, command-and-control (C2) communications, and modular design. We also provide indicators of compromise (IOCs), Microsoft Defender detections, and mitigation guidance to help organizations defend against this threat and related activity.<\/p>\n<h2 class=\"wp-block-heading\" id=\"observed-operators-and-targeting\">Observed operators and targeting<\/h2>\n<p class=\"wp-block-paragraph\">At the time of writing, Microsoft has observed at least one threat actor using NeedyMantis malware: Storm-3069. Storm-3069 is Microsoft Threat Intelligence\u2019s designator for activity associated with the DAEMON Tools supply chain compromise. While Microsoft assesses the activity originates from China, it has not attributed Storm-3069 to a Chinese nation-state actor. Microsoft identified NeedyMantis through follow-on analysis of indicators associated with Kaspersky\u2019s investigation of the DAEMON Tools compromise.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft has observed additional NeedyMantis activity beyond Storm-3069\u2019s activity in the DAEMON Tools campaign, indicating that the malware might be used by more than one operator. Observed activity involving NeedyMantis has thus far aligned with activity Microsoft associates with threat actors operating from China, such as targeting that aligns with Chinese interests and the use of selective deployment.<\/p>\n<p class=\"wp-block-paragraph\">NeedyMantis has been observed in intrusions affecting telecommunications organizations, universities, intergovernmental organizations, medical nonprofits, and government contractors. Combined with the malware\u2019s limited observed deployment and alignment with activity Microsoft associates with China-based threat actors, this victimology suggests NeedyMantis is deployed selectively rather than broadly. However, Microsoft has not determined whether all observed activity is attributable to the same threat actor or whether multiple actors have access to the malware.<\/p>\n<h2 class=\"wp-block-heading\" id=\"malware-packaging-and-distribution\">Malware packaging and distribution<\/h2>\n<p class=\"wp-block-paragraph\">As previously mentioned, observed activity suggests that the malware is typically deployed after a threat actor has established access to a target environment. As a result, the methods used to gain access before NeedyMantis is deployed may vary across intrusions.<\/p>\n<p class=\"wp-block-paragraph\">NeedyMantis is composed of multiple components written in C++ and x64 shellcode. The malware starts with a first-stage loader and a file archive. The loader and archive have been found packaged alongside legitimate software, with the first-stage loader\u2013masquerading as a required DLL\u2014being loaded through DLL sideloading.<\/p>\n<p class=\"wp-block-paragraph\">Some of the open-source, software abused by the malware include: Poedit (translation), curl (data transfer), Vim (text editor), and TightVNC (remote access). Microsoft has also observed NeedyMantis masquerading as Microsoft Office, Broadcom, Intel, and NVIDIA DLL components. The following is a list of some of the DLL path names used by the malware:<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><em>%ProgramFiles%\\<\/em><em>Poedit\\WinSparkle.dll<\/em><\/li>\n<li class=\"wp-block-list-item\"><em>%ProgramData%\\USOShared\\libcurl.dll<\/em><\/li>\n<li class=\"wp-block-list-item\"><em>%ProgramData%\\VIM\\vim64.dll<\/em><\/li>\n<li class=\"wp-block-list-item\"><em>%ProgramData%<\/em><em>\\TightVNC\\VIM\\vim64.dll<\/em><\/li>\n<li class=\"wp-block-list-item\"><em>%ProgramData%\\office\\dbghelp.dll<\/em><\/li>\n<li class=\"wp-block-list-item\"><em>%ProgramData%\\broadcom\\dbghelp.dll<\/em><\/li>\n<li class=\"wp-block-list-item\"><em>%ProgramData%\\Intel\\jli.dll<\/em><\/li>\n<li class=\"wp-block-list-item\"><em>%ProgramFiles%\\modifiable\\nvml.dll<\/em><\/li>\n<li class=\"wp-block-list-item\"><em>%ProgramData%\\ics\\nvml.dll<\/em><\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">The malware\u2019s file archive is named the same as the loader DLL without the extension, for example <em>WinSparkle<\/em> or <em>libcurl<\/em>.<\/p>\n<p class=\"wp-block-paragraph\">In one observed incident, an operator used the Impacket toolkit during hands-on-keyboard activity to copy the legitimate software, malicious DLL, and file archive from a network share and execute it on a targeted device. This activity occurred after the actor had already obtained access to the environment and illustrates one method by which NeedyMantis can be introduced during an intrusion post-compromise.<\/p>\n<p class=\"wp-block-paragraph\">NeedyMantis is observed during the post-compromise stage of an intrusion after an actor has established access to the target environment. While one known user of the malware, Storm-3069, has been associated with supply chain compromises, Microsoft has not observed NeedyMantis itself being distributed through a supply chain compromise. However, supply chain activity remains one possible means by which an actor could gain the access necessary to deploy the malware.<\/p>\n<h2 class=\"wp-block-heading\" id=\"needymantis-architecture-and-capabilities\">NeedyMantis architecture and capabilities<\/h2>\n<h3 class=\"wp-block-heading\" id=\"first-stage-loader\">First-stage loader<\/h3>\n<p class=\"wp-block-paragraph\">NeedyMantis\u2019 first-stage loader is DLL sideloaded and launched when the legitimate software it is packaged with is run. Its only task is to extract the second-stage loader from its file archive and continue execution there.<\/p>\n<p class=\"wp-block-paragraph\">In the analyzed sample, the loader DLL was named <em>WinSparkle.dll<\/em> (SHA-256: e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e) and its file archive was named <em>WinSparkle<\/em> (SHA-256: 9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef). NeedyMantis spoofed and replaced the <a href=\"https:\/\/winsparkle.org\/\">WinSparkle software update component<\/a> of the <a href=\"https:\/\/poedit.com\/\">Poedit translation software<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">The loader employs common anti-analysis techniques to hinder analysis, like obfuscating most of its important strings.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Figure-1.-Example-obfuscated-strings-being-deobfuscated.webp\" alt=\"A code snippet for x86 architecture manipulating memory addresses and performing data manipulation.\" class=\"wp-image-149662 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Figure-1.-Example-obfuscated-strings-being-deobfuscated.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 1. Example obfuscated strings being deobfuscated<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">This technique is known as obfuscated stack strings because each piece of the string is built up one at a time on the function\u2019s stack. Once built up, it is deobfuscated using various mathematical operations. Most of the obfuscated strings in this loader are Windows DLL and API names. These deobfuscated strings are used to resolve Windows APIs dynamically at runtime.<\/p>\n<p class=\"wp-block-paragraph\">In addition to obfuscated strings, a lot of the code\u2019s constant values are stored obfuscated as well.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Figure-2.-Example-obfuscated-constant-value-1032-being-deobfuscated.webp\" alt=\"C++ code performing a loop that manipulates a pointer to an integer array, incrementing an element, and then performing a calculation involving pointer arithmetic before a sleep function\" class=\"wp-image-149663 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Figure-2.-Example-obfuscated-constant-value-1032-being-deobfuscated.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 2. Example obfuscated constant value \u201c1032\u201d being deobfuscated<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">Finally, the loader has two anti-debugger methods: one based on <em>ProcessDebugFlags<\/em> and the other using <em>ThreadHideFromDebugger<\/em>.<\/p>\n<p class=\"wp-block-paragraph\">As noted above, the loader\u2019s main objective is to extract the next stage from its file archive and launch it. In the analyzed sample, the next stage was named <em>encryptbase64.ps1<\/em>.<\/p>\n<h3 class=\"wp-block-heading\" id=\"custom-file-archives\">Custom file archives<\/h3>\n<p class=\"wp-block-paragraph\">NeedyMantis\u2019 file archives are in an encrypted and compressed custom file format. To get access to the files, the outer layer of the archive is XOR-decoded and <em>RtlDecompressBuffer<\/em> decompressed. Once decompressed, there are individual file entries. In each file entry, the file\u2019s name is XOR-decoded and its contents are <em>RtlDecompressBuffer<\/em> decompressed.<\/p>\n<p class=\"wp-block-paragraph\">The file format\u2019s offsets, XOR keys, and values change from sample to sample.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Figure-3.-Example-output-of-an-archive-unpacking-tool-displaying-metadata-of-the-WinSparkle-file-archive.webp\" alt=\"A hexadecimal data structure depicting a file's header, containing information such as checksums, entry counts, and sizes for various compressed files.\" class=\"wp-image-149664 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Figure-3.-Example-output-of-an-archive-unpacking-tool-displaying-metadata-of-the-WinSparkle-file-archive.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 3. Example output of an archive unpacking tool displaying metadata of the WinSparkle file archive<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">This archive contains the following 11 files:<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><em>7-zip.chm<\/em> \u2013 Legitimate component of 7-Zip<\/li>\n<li class=\"wp-block-list-item\"><em>7-zip.dll<\/em> \u2013 Legitimate component of 7-Zip<\/li>\n<li class=\"wp-block-list-item\"><em>7-zip32.dll<\/em> \u2013 Legitimate component of 7-Zip<\/li>\n<li class=\"wp-block-list-item\"><em>7z.exe<\/em> \u2013 Legitimate component of 7-Zip<\/li>\n<li class=\"wp-block-list-item\"><em>Disk2vhd.dll<\/em> \u2013 Legitimate Sysinternals component <em>Disk2vhd<\/em><\/li>\n<li class=\"wp-block-list-item\"><em>main.dll<\/em> \u2013 Legitimate Sysinternals component <em>Ctrl2Cap<\/em><\/li>\n<li class=\"wp-block-list-item\"><em>kernel32.dll<\/em> \u2013 Legitimate <em>kernel32.dll<\/em><\/li>\n<li class=\"wp-block-list-item\"><em>encryptbase64.ps1<\/em> \u2013 Second-stage loader<\/li>\n<li class=\"wp-block-list-item\"><em>dnsapi.dll<\/em> \u2013 Not a <em>dnsapi.dll<\/em>, but contains the malware\u2019s configuration<\/li>\n<li class=\"wp-block-list-item\"><em>ws2_32.dll<\/em> \u2013 Not a <em>ws2_32.dll<\/em>, but contains a WebSockets based communications DLL<\/li>\n<li class=\"wp-block-list-item\"><em>msvcrt140.dll<\/em> \u2013 Not a <em>msvcrt140.dll<\/em>, but contains shellcode to load module DLLs and resolve exports<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">While this archive contains several legitimate software components, the malware\u2019s functionality is implemented by the remaining files, discussed below.<\/p>\n<p class=\"wp-block-paragraph\">Other analyzed NeedyMantis file archives have contained different file names and components. An older version of the malware, for example, used a <em>libcurl<\/em> (SHA-256: c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77) file archive, and it contained only four files:<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><em>300.c<\/em> \u2013 Malware\u2019s configuration<\/li>\n<li class=\"wp-block-list-item\"><em>300.s<\/em> \u2013 WebSockets-based communications DLL<\/li>\n<li class=\"wp-block-list-item\"><em>is<\/em> \u2013 Persistence module using Windows Services<\/li>\n<li class=\"wp-block-list-item\"><em>m.l<\/em> \u2013 Main component<\/li>\n<\/ul>\n<h3 class=\"wp-block-heading\" id=\"second-stage-loader\">Second-stage loader<\/h3>\n<p class=\"wp-block-paragraph\">In the analyzed sample, <em>encryptbase64.ps1<\/em> was the second-stage loader. Despite its <em>.ps1<\/em> PowerShell extension, the file contains x64 shellcode. Its purpose is to decode and decompress an embedded binary which is NeedyMantis\u2019 main component.<\/p>\n<p class=\"wp-block-paragraph\">This loader also has some anti-analysis functionality that differs from stage one. For string decoding, it locates two encoded blocks of data and XOR keys at calculated offsets and then decodes them. The first block, most relevantly, contains a few Windows DLL and API names that are resolved dynamically. The second block, shown below, contains a list of Windows DLL names and Windows API hash values:<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Figure-4.-Decoded-Windows-API-hash-values.webp\" alt=\"A list of hexadecimal numbers depicting a list of Windows DLL names and Windows API hash values.\" class=\"wp-image-149665 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Figure-4.-Decoded-Windows-API-hash-values.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 4. Decoded Windows API hash values<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">The component uses a rotate right (ROR) based algorithm with a configurable rotation value (the analyzed sample used value <em>11<\/em>) to resolve these Windows API hashes. Figure 5 shows a snippet of Python code reproducing the algorithm:<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Figure-5.-Python-snippet-of-Windows-API-hashing-algorithm.webp\" alt=\"A snippet of Python code, which includes two function definitions.\n`ror(num, count, size)`: and `resolve(func, name)`: \" class=\"wp-image-149666 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Figure-5.-Python-snippet-of-Windows-API-hashing-algorithm.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 5. Python snippet of Windows API hashing algorithm<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">This second-stage loader\u2019s objective is to extract embedded data, XOR-decode it, and then <em>RtlDecompressBuffer<\/em> decompress it. The location of the encoded data and XOR key are at calculated offsets, which change from sample to sample.<\/p>\n<p class=\"wp-block-paragraph\">Once decoded the resulting data is a DLL that has been formatted using a custom executable file format. It is a minimized version of a PE file.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/image-63.webp\" alt=\"Code depicting various metadata and section headers, including offset, base addresses, size, and various attributes for different sections such as '.text', '.rdata', '.data', and '.reloc'.\" class=\"wp-image-149660 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/image-63.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 6. Example output of custom executable file format to PE file conversion tool<\/em><\/figcaption><\/figure>\n<h3 class=\"wp-block-heading\" id=\"main-component\">Main component<\/h3>\n<p class=\"wp-block-paragraph\">NeedyMantis\u2019 main component orchestrates C2 communications and handles additional downloaded modules.<\/p>\n<p class=\"wp-block-paragraph\">It creates a mutex named <em>&lt;username&gt;-&lt;process name&gt;<\/em>, such as <em>Contoso-Poedit.exe<\/em>. Like in the first-stage loader, most of the main component\u2019s strings and constant values are stored as obfuscated stack strings.<\/p>\n<h4 class=\"wp-block-heading\" id=\"configuration\">Configuration<\/h4>\n<p class=\"wp-block-paragraph\">The malware\u2019s configuration was stored in a <em>dnsapi.dll<\/em> file from the custom file archive. This file name spoofs a Windows networking library. In the sample analyzed, the file contains a 3448-byte binary structure. The structure includes the following fields:<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><em>0x00<\/em>: Unknown (config contained \u201c300\u201d, but components also reference \u201c400\u201d)<\/li>\n<li class=\"wp-block-list-item\"><em>0x1c<\/em>: Communication component name (<em>ws2_32.dll<\/em>)<\/li>\n<li class=\"wp-block-list-item\"><em>0x128<\/em>: C2 port (443)<\/li>\n<li class=\"wp-block-list-item\"><em>0x12c<\/em>: C2 host (<em>corp.tripswithengine[.]com<\/em>)<\/li>\n<li class=\"wp-block-list-item\"><em>0x334<\/em>: C2 URI (<em>\/library\/zip\/<\/em>)<\/li>\n<li class=\"wp-block-list-item\"><em>0x53C<\/em>: <em>WinHttpOpen AccessType<\/em> (0)<\/li>\n<li class=\"wp-block-list-item\"><em>0x954<\/em>: Proxy username (not set)<\/li>\n<li class=\"wp-block-list-item\"><em>0xB5C<\/em>: Proxy password (not set)<\/li>\n<li class=\"wp-block-list-item\"><em>0xD64<\/em>: Sleep time related (300)<\/li>\n<li class=\"wp-block-list-item\"><em>0xD68<\/em>: Sleep time related (300)<\/li>\n<\/ul>\n<h4 class=\"wp-block-heading\" id=\"communications-dll\">Communications DLL<\/h4>\n<p class=\"wp-block-paragraph\">As referenced in the configuration, NeedyMantis makes use of a communication component called <em>ws2_32.dll<\/em>. This component is also stored in the custom file archive. Like the config file, the file name spoofs a Windows networking library.<\/p>\n<p class=\"wp-block-paragraph\">This communications DLL has one export named <em>SystemInfo<\/em>. As shown below in Figure 7, SystemInfo exposes 10 functions for the main component to initiate and maintain a WebSockets connection with the C2:<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Figure-7.-Communications-DLL-API-functions.webp\" alt=\"A sequence of function declarations for a communication system, including open, close, connect, send, receive, and placeholder functions.\" class=\"wp-image-149667 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Figure-7.-Communications-DLL-API-functions.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 7. Communications DLL API functions<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">The library uses WinINet APIs for WebSockets. It also has a hard-coded user-agent of <em>firefox\/21.0<\/em>.<\/p>\n<p class=\"wp-block-paragraph\">We have also spotted a second version of the communications DLL in a file archive. It implements the same communications API but uses Libwebsockets (LWS) instead of WinINet.<\/p>\n<h4 class=\"wp-block-heading\" id=\"command-and-control\">Command and control<\/h4>\n<p class=\"wp-block-paragraph\">The initial C2 beacon is an HTTPS GET request, similar to Figure 8 below:<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/image-64.webp\" alt=\"An HTTP request for a ZIP file in a web browser, specifying various cache control and connection settings.\" class=\"wp-image-149655 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/image-64.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 8. Initial C2 HTTPS GET request<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">The <em>Set-Cookie<\/em> header contains system information. The header value can be Base64-decoded and <em>RtlDecompressBuffer<\/em> decompressed. Once decompressed it contains a JSON object. The key values are:<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><em>c<\/em> \u2013 Computer name<\/li>\n<li class=\"wp-block-list-item\"><em>u<\/em> \u2013 Username<\/li>\n<li class=\"wp-block-list-item\"><em>o<\/em> \u2013 Base64-encoded data, once decoded it contains line separated \u201c<key>: <value>\u201d entries\n<ul>\n<li><em>p<\/em> \u2013 Process name<\/li>\n<\/ul>\n<ul>\n<li><em>pa<\/em> \u2013 Parent process<\/li>\n<\/ul>\n<ul>\n<li><em>f<\/em> \u2013 Files in <em>ProgramFiles<\/em> directory<\/li>\n<\/ul>\n<p><\/value><\/key><\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><em>p<\/em> \u2013 Process list<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">The connection is then converted to WebSockets and a binary C2 protocol is continued. The binary protocol is separated into a header and optional data components. The 44-byte header includes the following fields:<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><em>0x00<\/em>: 16-byte XOR key<\/li>\n<li class=\"wp-block-list-item\"><em>0x10<\/em>: Uncompressed data length<\/li>\n<li class=\"wp-block-list-item\"><em>0x14<\/em>: Compressed data length<\/li>\n<li class=\"wp-block-list-item\"><em>0x18<\/em>: Command number<\/li>\n<li class=\"wp-block-list-item\"><em>0x28<\/em>: Data length<\/li>\n<li class=\"wp-block-list-item\"><em>0x2c<\/em>: Optional data<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">A 16-byte random XOR key is generated and the header is XOR-encoded, starting at offset <em>0x18<\/em>. If there is any data, it is compressed with <em>RtlCompressBuffer<\/em> and optionally encrypted with RC4.<\/p>\n<p class=\"wp-block-paragraph\">The initial messages of the binary protocol are a key exchange with the C2 server. The protocol is performed as such:<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">32-bytes are received from the C2 server, but then ignored<\/li>\n<li class=\"wp-block-list-item\">A 1024-byte random buffer is created<\/li>\n<li class=\"wp-block-list-item\">The first 32-bytes of this random buffer are used as the RC4 key for further communications<\/li>\n<li class=\"wp-block-list-item\">A 256-byte buffer is created that starts with <em>google.com<\/em> followed by random bytes<\/li>\n<li class=\"wp-block-list-item\">The 256-byte buffer is RC4 encrypted<\/li>\n<li class=\"wp-block-list-item\">A random length between 292 and 1282 is picked<\/li>\n<li class=\"wp-block-list-item\">The C2 protocol message data is structured as such:\n<ul>\n<li><em>0x00<\/em>: The random length<\/li>\n<\/ul>\n<ul>\n<li><em>0x04<\/em>: RC4 encrypted <em>google.com<\/em> buffer<\/li>\n<\/ul>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><em>0x104<\/em>: The random 1024-byte buffer used to create the RC4 key (at least 32 bytes of it)<\/li>\n<\/ul>\n<\/li>\n<li class=\"wp-block-list-item\">This message data is compressed, but not RC4 encrypted<\/li>\n<li class=\"wp-block-list-item\">A random command number between 1 and 45 is chosen<\/li>\n<li class=\"wp-block-list-item\">The C2 server uses the buffer at offset <em>0x104<\/em> to recreate the RC4 key and presumably checks the RC4 encrypted <em>google.com<\/em> buffer<\/li>\n<li class=\"wp-block-list-item\">The server sends back the random command number as an acknowledgement<\/li>\n<\/ul>\n<h4 class=\"wp-block-heading\" id=\"commands\">Commands<\/h4>\n<p class=\"wp-block-paragraph\">The main component only has a handful of commands. Commands sent to the C2 include:<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><em>1110<\/em> \u2013 Sends computer name and username<\/li>\n<li class=\"wp-block-list-item\"><em>1112<\/em> \u2013 Sends a hard-coded identifier (like <em>20001<\/em>)<\/li>\n<li class=\"wp-block-list-item\"><em>1150<\/em> \u2013 Keep alive<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">Commands received from the C2 include:<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><em>1020<\/em> \u2013 Load module<\/li>\n<li class=\"wp-block-list-item\"><em>1030<\/em> \u2013 Unload module<\/li>\n<li class=\"wp-block-list-item\"><em>1050<\/em> \/ <em>1150<\/em> \u2013 Dispatch data to module<\/li>\n<li class=\"wp-block-list-item\"><em>1070<\/em> \u2013 Turn off active flags<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">The main component\u2019s load, unload, and data dispatch commands show that NeedyMantis can extend its functionality through additional modules, but the capabilities of those modules remain unconfirmed.<\/p>\n<h2 class=\"wp-block-heading\" id=\"mitigation-and-protection-guidance\">Mitigation and protection guidance<\/h2>\n<p class=\"wp-block-paragraph\">Microsoft recommends the following mitigations to reduce the impact of this threat.<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Look for outbound connections in network egress traffic to <em>corp.tripswithengine[.]com<\/em>.<\/li>\n<li class=\"wp-block-list-item\">Turn on <a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/enable-cloud-protection-microsoft-defender-antivirus\">cloud-delivered protection<\/a> and <a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/configure-block-at-first-sight-microsoft-defender-antivirus\">block at first sight<\/a> to rapidly identify and block new and unknown malware variants.<\/li>\n<li class=\"wp-block-list-item\">Run <a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/edr-in-block-mode\" target=\"_blank\" rel=\"noreferrer noopener\">Endpoint Detection and Response\u202f(EDR) in block mode<\/a>\u202fso that Microsoft Defender for Endpoint can block malicious artifacts, even when your non-Microsoft antivirus does not detect the threat or when Microsoft Defender Antivirus is running in passive mode. EDR in block mode works behind the scenes to remediate malicious artifacts that are detected post-breach.\u202f\u202f\u202f\u202f <\/li>\n<li class=\"wp-block-list-item\">Enable <a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/enable-network-protection\" target=\"_blank\" rel=\"noreferrer noopener\">network protection<\/a> in Microsoft Defender for Endpoint. <\/li>\n<li class=\"wp-block-list-item\">Configure <a href=\"https:\/\/learn.microsoft.com\/defender-xdr\/configure-attack-disruption\" target=\"_blank\" rel=\"noreferrer noopener\">automatic attack disruption<\/a> in Microsoft Defender XDR. Automatic attack disruption is designed to contain attacks in progress, limit the impact on an organization\u2019s assets, and provide more time for security teams to remediate the attack fully. <\/li>\n<li class=\"wp-block-list-item\">Microsoft Defender XDR customers can turn on the following <a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/attack-surface-reduction-rules-overview\" target=\"_blank\" rel=\"noopener noreferrer\">attack surface reduction rules<\/a>\u202fto prevent common attack techniques used by threat actors. <\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">You can assess how an attack surface reduction rule might impact your network by opening the <a href=\"https:\/\/security.microsoft.com\/security-recommendations\">security recommendation<\/a> for that rule in threat and vulnerability management. In the recommendation details pane, check the user impact to determine what percentage of your devices can accept a new policy enabling the rule in blocking mode without adverse impact to user productivity.<\/p>\n<h3 class=\"wp-block-heading\" id=\"microsoft-defender-detections\">Microsoft Defender detections<\/h3>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.microsoft.com\/security\/business\/microsoft-defender\">Microsoft Defender<\/a> customers can refer to the list of applicable detections below. Microsoft Defender coordinates detection, prevention, investigation, and response across endpoints, identities, email, apps to provide integrated protection against attacks like the threat discussed in this blog.<\/p>\n<figure class=\"wp-block-table\" data-table-col-widths=\"[151,245,284]\"><\/figure>\n<h3 class=\"wp-block-heading\" id=\"microsoft-security-copilot\">Microsoft Security Copilot<\/h3>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/ai-machine-learning\/microsoft-security-copilot\">Microsoft Security Copilot<\/a> is <a href=\"https:\/\/learn.microsoft.com\/defender-xdr\/security-copilot-in-microsoft-365-defender\">embedded in Microsoft Defender<\/a> and provides security teams with AI-powered capabilities to summarize incidents, analyze files and scripts, summarize identities, use guided responses, and generate device summaries, hunting queries, and incident reports.<\/p>\n<p class=\"wp-block-paragraph\">Customers can also <a href=\"https:\/\/learn.microsoft.com\/defender-xdr\/security-copilot-agents-defender\">deploy AI agents<\/a>, including the following <a href=\"https:\/\/learn.microsoft.com\/copilot\/security\/agents-overview\">Microsoft Security Copilot agents<\/a>, to perform security tasks efficiently:<\/p>\n<p class=\"wp-block-paragraph\">Security Copilot is also available as a <a href=\"https:\/\/learn.microsoft.com\/en-us\/copilot\/security\/experiences-security-copilot\">standalone experience<\/a> where customers can perform specific security-related tasks, such as incident investigation, user analysis, and vulnerability impact assessment. In addition, Security Copilot offers <a href=\"https:\/\/learn.microsoft.com\/copilot\/security\/developer\/custom-agent-overview\">developer scenarios<\/a> that allow customers to build, test, publish, and integrate AI agents and plugins to meet unique security needs.<\/p>\n<h3 class=\"wp-block-heading\" id=\"threat-intelligence-reports\">Threat intelligence reports<\/h3>\n<p class=\"wp-block-paragraph\">Microsoft Defender XDR customers can use the following <a href=\"https:\/\/learn.microsoft.com\/defender-xdr\/threat-analytics\">threat analytics<\/a> reports in the Defender portal (requires license for at least one Defender XDR product) to get the most up-to-date information about the threat actor, malicious activity, and techniques discussed in this blog. These reports provide the intelligence, protection information, and recommended actions to prevent, mitigate, or respond to associated threats found in customer environments.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft Security Copilot customers can also use the <a href=\"https:\/\/learn.microsoft.com\/defender\/threat-intelligence\/security-copilot-and-defender-threat-intelligence?bc=%2Fsecurity-copilot%2Fbreadcrumb%2Ftoc.json&amp;toc=%2Fsecurity-copilot%2Ftoc.json#turn-on-the-security-copilot-integration-in-defender-ti\">Microsoft Security Copilot integration<\/a> in Microsoft Defender Threat Intelligence, either in the Security Copilot standalone portal or in the <a href=\"https:\/\/learn.microsoft.com\/defender\/threat-intelligence\/using-copilot-threat-intelligence-defender-xdr\">embedded experience<\/a> in the Microsoft Defender portal to get more information about this malware and associated activity.<\/p>\n<h2 class=\"wp-block-heading\" id=\"hunting-queries\">Hunting queries<\/h2>\n<h3 class=\"wp-block-heading\" id=\"microsoft-defender-xdr\">Microsoft Defender XDR<\/h3>\n<p class=\"wp-block-paragraph\">Microsoft Defender XDR customers can run the following <a href=\"https:\/\/learn.microsoft.com\/defender-xdr\/advanced-hunting-overview\">advanced hunting<\/a> queries to find related activity in their networks:<\/p>\n<p class=\"wp-block-paragraph\"><strong>NeedyMantis masquerading as software<\/strong><\/p>\n<p class=\"wp-block-paragraph\">A listing of legitimate, unmodified application folders, along with malicious replacement DLL filenames sideloaded by NeedyMantis.<\/p>\n<div class=\"wp-block-syntaxhighlighter-code \" readability=\"31\">\n<pre class=\"brush: plain; auto-links: false; gutter: false; title: ; quick-code: false; notranslate\" title>\nDeviceFileEvents\n| where Timestamp &gt; ago(7d)\n| where ( (FolderPath matches regex @\"^[A-Za-z]:\\\\Program Files\\\\Poedit\" and FileName == \"WinSparkle.dll\") or (FolderPath matches regex @\"^[A-Za-z]:\\\\Program Files \\(x86\\)\\\\Poedit\" and FileName == \"WinSparkle.dll\") or (FolderPath matches regex @\"^[A-Za-z]:\\\\ProgramData\\\\USOShared\" and FileName == \"libcurl.dll\") or (FolderPath matches regex @\"^[A-Za-z]:\\\\ProgramData\\\\VIM\" and FileName == \"vim64.dll\") or (FolderPath matches regex @\"^[A-Za-z]:\\\\ProgramData\\\\TightVNC\\\\VIM\" and FileName == \"vim64.dll\") or (FolderPath matches regex @\"^[A-Za-z]:\\\\ProgramData\\\\office\" and FileName == \"dbghelp.dll\") or (FolderPath matches regex @\"^[A-Za-z]:\\\\ProgramData\\\\broadcom\" and FileName == \"dbghelp.dll\") or (FolderPath matches regex @\"^[A-Za-z]:\\\\ProgramData\\\\Intel\" and FileName == \"jli.dll\") or (FolderPath matches regex @\"^[A-Za-z]:\\\\Program Files\\\\modifiable\" and FileName == \"nvml.dll\") or (FolderPath matches regex @\"^[A-Za-z]:\\\\Program Files \\(x86\\)\\\\modifiable\" and FileName == \"nvml.dll\") or (FolderPath matches regex @\"^[A-Za-z]:\\\\ProgramData\\\\ics\" and FileName == \"nvml.dll\")\n)\n| project Timestamp, DeviceId, DeviceName, ActionType, FolderPath, FileName, SHA1, SHA256, MD5, InitiatingProcessAccountDomain, InitiatingProcessAccountName, InitiatingProcessAccountSid, InitiatingProcessAccountUpn, InitiatingProcessMD5, InitiatingProcessSHA1, InitiatingProcessSHA256, InitiatingProcessFolderPath, InitiatingProcessFileName, InitiatingProcessCommandLine, InitiatingProcessCreationTime, ReportId, TenantId\n<\/pre>\n<\/div>\n<p class=\"wp-block-paragraph\"><strong>NeedyMantis C2<\/strong><\/p>\n<p class=\"wp-block-paragraph\">This query identifies connectivity to the NeedyMantis command and control site for this activity.<\/p>\n<div class=\"wp-block-syntaxhighlighter-code \" readability=\"36\">\n<pre class=\"brush: plain; gutter: false; title: ; quick-code: false; notranslate\" title>\nsearch in (DeviceNetworkEvents, EmailUrlInfo, UrlClickEvents, DeviceEvents, DeviceFileEvents, DeviceProcessEvents) \"corp.tripswithengine.com\"\n| where Timestamp &gt; ago(7d)\n| extend SourceTable = $table\n| project Timestamp, DeviceName, InitiatingProcessAccountName, InitiatingProcessAccountUpn, AccountName, AccountUpn, RemoteIP, LocalIP, IPAddress, RemoteUrl, Url, UrlDomain, FileOriginUrl, FileOriginReferrerUrl, FileOriginIP, ProcessCommandLine, InitiatingProcessCommandLine, InitiatingProcessFileName, FileName, FolderPath, NetworkMessageId, SourceTable\n<\/pre>\n<\/div>\n<p class=\"wp-block-paragraph\"><strong>NeedyMantis communications DLL hard-coded user-agent<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Identify connectivity utilizing the NeedyMantis hard-coded user-agent.<\/p>\n<div class=\"wp-block-syntaxhighlighter-code \" readability=\"30\">\n<pre class=\"brush: plain; auto-links: false; gutter: false; title: ; quick-code: false; notranslate\" title>\nsearch in (DeviceNetworkEvents, DeviceEvents, UrlClickEvents, EmailUrlInfo) \"Firefox\/21.0\"\n| where Timestamp &gt; ago(7d)\n| extend SourceTable = $table\n| project Timestamp, DeviceName = iff(isnull(DeviceName), \"\", DeviceName), AccountUpn = coalesce(InitiatingProcessAccountUpn, AccountUpn, \"\"), AccountName = coalesce(InitiatingProcessAccountName, AccountName, \"\"), RemoteIP = coalesce(RemoteIP, IPAddress, \"\"), Url = coalesce(RemoteUrl, Url, \"\"), UserAgent = AdditionalFields, SourceTable\n<\/pre>\n<\/div>\n<h3 class=\"wp-block-heading\" id=\"microsoft-sentinel\">Microsoft Sentinel<\/h3>\n<p class=\"wp-block-paragraph\">Microsoft Sentinel customers can use the TI Mapping analytics (a series of analytics all prefixed with \u2018TI map\u2019) to automatically match the malicious domain indicators mentioned in this blog post with data in their workspace. If the TI Map analytics are not currently deployed, customers can install the Threat Intelligence solution from the <a href=\"https:\/\/learn.microsoft.com\/azure\/sentinel\/sentinel-solutions-deploy\">Microsoft Sentinel Content Hub<\/a> to have the analytics rule deployed in their Sentinel workspace.<\/p>\n<p class=\"wp-block-paragraph\"><strong>NeedyMantis C2<\/strong><\/p>\n<p class=\"wp-block-paragraph\">This query identifies connectivity to the NeedyMantis command and control site for this activity.<\/p>\n<div class=\"wp-block-syntaxhighlighter-code \" readability=\"27\">\n<pre class=\"brush: plain; auto-links: false; gutter: false; title: ; quick-code: false; notranslate\" title>\nsearch in (CommonSecurityLog, SecurityEvent, AzureDiagnostics) \"corp.tripswithengine.com\"\n| where TimeGenerated &gt; ago(7d)\n| project TimeGenerated, DeviceName, Computer, SourceIP, SourcePort, SourceUserName, DestinationIP, DestinationPort, DestinationHostName, DestinationDnsDomain, RequestURL, ProcessName, DestinationUserName, SourceHostName, Message, $table\n<\/pre>\n<\/div>\n<p class=\"wp-block-paragraph\"><strong>NeedyMantis communications DLL hard-code user-agent<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Identify connectivity utilizing the NeedyMantis hard-code user-agent.<\/p>\n<div class=\"wp-block-syntaxhighlighter-code \" readability=\"15\">\n<pre class=\"brush: plain; auto-links: false; gutter: false; title: ; quick-code: false; notranslate\" title>\nCommonSecurityLog\n| where TimeGenerated &gt; ago(7d)\n| where RequestClientApplication contains \"Firefox\/21.0\" or Message contains \"Firefox\/21.0\"\n| project TimeGenerated, DeviceName, SourceUserName, SourceIP, DestinationIP, RequestURL, RequestClientApplication\n<\/pre>\n<\/div>\n<h2 class=\"wp-block-heading\" id=\"indicators-of-compromise\">Indicators of compromise<\/h2>\n<figure class=\"wp-block-table\" data-table-col-widths=\"[207,101,152,109,111]\">\n<table class=\"has-fixed-layout\">\n<tbody readability=\"7\">\n<tr>\n<td><strong>Indicator<\/strong><\/td>\n<td><strong>Type<\/strong><\/td>\n<td><strong>Description<\/strong><\/td>\n<td><strong>First seen<\/strong><\/td>\n<td><strong>Last seen<\/strong><\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e<\/td>\n<td> SHA-256<\/td>\n<td>First-stage loader <em>WinSparkle.dll<\/em><\/td>\n<td> 2026-05-21<\/td>\n<td> 2026-05-21<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef<\/td>\n<td>SHA-256<\/td>\n<td>Custom file archive <em>WinSparkle<\/em><\/td>\n<td> 2026-05-23<\/td>\n<td> 2026-05-23<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77<\/td>\n<td>SHA-256<\/td>\n<td>Custom file archive <em>libcurl<\/em><\/td>\n<td>2025-10-03<\/td>\n<td>2025-10-03<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td><em>corp.tripswithengine[.]com<\/em><\/td>\n<td>Host name<\/td>\n<td>C2 host name<\/td>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h3 class=\"wp-block-heading\" id=\"references\">References<\/h3>\n<h3 class=\"wp-block-heading\" id=\"learn-more\">Learn more<\/h3>\n<p class=\"wp-block-paragraph\">For the latest security research from the Microsoft Threat Intelligence community, check out the <a href=\"https:\/\/aka.ms\/threatintelblog\">Microsoft Threat Intelligence Blog<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">To get notified about new publications and to join discussions on social media, follow us on <a href=\"https:\/\/www.linkedin.com\/showcase\/microsoft-threat-intelligence\">LinkedIn<\/a>, <a href=\"https:\/\/x.com\/MsftSecIntel\">X (formerly Twitter)<\/a>, and <a href=\"https:\/\/bsky.app\/profile\/threatintel.microsoft.com\">Bluesky<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the <a href=\"https:\/\/thecyberwire.com\/podcasts\/microsoft-threat-intelligence\">Microsoft Threat Intelligence podcast<\/a>.<\/p>\n<p>READ MORE <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/09\/28\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components to maintain long-term access and support follow-on operations.<br \/>\nThe post NeedyMantis: Unpacking a post-compromise malware family used in targeted operations appeared first on Microsoft Security Blog. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[28,10798],"class_list":["post-61429","post","type-post","status-publish","format-standard","hentry","category-microsoft-secure","tag-malware","tag-storm"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>NeedyMantis: Unpacking a post-compromise malware family used in targeted operations 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NeedyMantis: Unpacking a post-compromise malware family used in targeted operations 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-28T15:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"432\" \/>\n\t<meta property=\"og:image:height\" content=\"435\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"17 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"NeedyMantis: Unpacking a post-compromise malware family used in targeted operations\",\"datePublished\":\"2026-09-28T15:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\\\/\"},\"wordCount\":3044,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.microsoft.com\\\/en-us\\\/security\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Figure-1.-Example-obfuscated-strings-being-deobfuscated.webp\",\"keywords\":[\"Malware\",\"Storm\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\\\/\",\"name\":\"NeedyMantis: Unpacking a post-compromise malware family used in targeted operations 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.microsoft.com\\\/en-us\\\/security\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Figure-1.-Example-obfuscated-strings-being-deobfuscated.webp\",\"datePublished\":\"2026-09-28T15:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.microsoft.com\\\/en-us\\\/security\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Figure-1.-Example-obfuscated-strings-being-deobfuscated.webp\",\"contentUrl\":\"https:\\\/\\\/www.microsoft.com\\\/en-us\\\/security\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Figure-1.-Example-obfuscated-strings-being-deobfuscated.webp\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Malware\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/malware\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"NeedyMantis: Unpacking a post-compromise malware family used in targeted operations\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NeedyMantis: Unpacking a post-compromise malware family used in targeted operations 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\/","og_locale":"en_US","og_type":"article","og_title":"NeedyMantis: Unpacking a post-compromise malware family used in targeted operations 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2026-09-28T15:00:00+00:00","og_image":[{"width":432,"height":435,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"17 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"NeedyMantis: Unpacking a post-compromise malware family used in targeted operations","datePublished":"2026-09-28T15:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\/"},"wordCount":3044,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\/#primaryimage"},"thumbnailUrl":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Figure-1.-Example-obfuscated-strings-being-deobfuscated.webp","keywords":["Malware","Storm"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\/","url":"https:\/\/www.threatshub.org\/blog\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\/","name":"NeedyMantis: Unpacking a post-compromise malware family used in targeted operations 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\/#primaryimage"},"thumbnailUrl":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Figure-1.-Example-obfuscated-strings-being-deobfuscated.webp","datePublished":"2026-09-28T15:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\/#primaryimage","url":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Figure-1.-Example-obfuscated-strings-being-deobfuscated.webp","contentUrl":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Figure-1.-Example-obfuscated-strings-being-deobfuscated.webp"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Malware","item":"https:\/\/www.threatshub.org\/blog\/tag\/malware\/"},{"@type":"ListItem","position":3,"name":"NeedyMantis: Unpacking a post-compromise malware family used in targeted operations"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61429","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=61429"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61429\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=61429"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=61429"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=61429"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}