MICROSOFT Threat Intelligence has identified NeedyMantis, a modular post-compromise malware family used in a limited number of targeted intrusions against telecommunications organisations, universities, medical non-profits, intergovernmental organisations and government contractors. Activity dates back to at least October 2025. Microsoft says the malware is generally deployed after attackers have already gained access, helping them maintain long-term access and conduct follow-on operations.
At least one observed user is Storm-3069, the group Microsoft associates with the DAEMON Tools supply-chain compromise, although Microsoft has not attributed the activity to a specific Chinese state actor or established that all deployments share one operator.
The malware uses DLL sideloading, masquerading as components of software including Poedit, curl, Vim and TightVNC, as well as Microsoft Office, Broadcom, Intel and NVIDIA libraries. Its stages use encrypted and compressed custom archives, obfuscated strings, anti-debugging checks, shellcode and a minimised custom executable format.
The main component communicates over HTTPS before switching to WebSockets, using the C2 host `corp.tripswithengine[.]com` and the hard-coded user-agent `firefox/21.0`; its modular design allows operators to load, unload and communicate with additional modules, although their capabilities remain unconfirmed.
Microsoft recommends investigating connections to the domain and suspicious replacement DLLs, while Defender customers can use detections including TrojanDropper:Win64/NeedyMantis and Behavior:Win64/NeedyMantis, alongside cloud protection, EDR in block mode, network protection and relevant attack-surface-reduction rules.