Microsoft Threat Intelligence has pulled apart a modular backdoor it calls NeedyMantis, which operators have been quietly slipping into telecommunications companies, universities, medical nonprofits, intergovernmental organizations and government contractors since at least October 2025. The malware hides behind legitimate programs such as the Poedit translation tool, Vim, curl and TightVNC, and is built to hold a foothold open long after the initial break-in.
Microsoft says the activity it has seen so far aligns with threat actors it associates with operating from China, based on targeting that fits Chinese interests and the selective way the malware is deployed. It has stopped short of attributing the activity to a Chinese nation-state actor, and it has not determined whether every intrusion is the work of the same operator. The full analysis is in Microsoft's original report.
A thread pulled from the DAEMON Tools compromise
Microsoft found NeedyMantis by pivoting from indicators tied to the DAEMON Tools supply chain compromise, which Kaspersky investigated. Microsoft tracks the actor behind that campaign as Storm-3069, the one operator it has confirmed using NeedyMantis. It has also seen NeedyMantis activity outside Storm-3069's campaign, which suggests the malware might be used by more than one group.
One detail matters for defenders: Microsoft has not seen NeedyMantis itself spread through a supply chain compromise. It arrives after the attackers are already inside. In one incident, an operator used the Impacket toolkit during hands-on-keyboard activity to copy a legitimate program, the malicious DLL and an encrypted archive from a network share and run them on a target machine. For how software supply chain attacks have been shifting, see our earlier coverage.
Borrowed programs, fake Windows files
The infection chain starts with DLL sideloading, where a trusted program is tricked into loading a malicious library placed next to it. In the sample Microsoft analyzed, the malware replaced WinSparkle.dll, Poedit's software update component. Other samples masqueraded as Microsoft Office, Broadcom, Intel and NVIDIA components, using paths such as %ProgramData%\USOShared\libcurl.dll, %ProgramData%\Intel\jli.dll and %ProgramData%\ics\nvml.dll.
That first loader's only job is to unpack the next stage from a custom encrypted archive named after the DLL. The archive Microsoft examined held 11 files, several of them genuine 7-Zip and Sysinternals components, alongside files posing as Windows libraries: a fake dnsapi.dll carrying the configuration, a fake ws2_32.dll handling network traffic, and a second-stage loader named encryptbase64.ps1 that is actually x64 shellcode rather than a PowerShell script. Both loaders use string obfuscation, and the first adds anti-debugging checks. The main component is stored in a stripped-down custom executable format.
A WebSocket channel built for add-ons
Once running, NeedyMantis beacons over HTTPS on port 443, packing the computer name, username, process list and installed programs into a compressed cookie, then upgrades the connection to WebSockets with an RC4-encrypted binary protocol. The core implant has only a handful of commands, mostly to load, unload and pass data to additional modules. Microsoft notes that what those modules can do remains unconfirmed.
Block the C2 domain and hunt for sideloaded DLLs
Microsoft recommends checking egress traffic for connections to the command-and-control host, turning on cloud-delivered protection and block at first sight, running EDR in block mode, and enabling the attack surface reduction rules that block low-prevalence executables and potentially obfuscated scripts. Defender detects the malware as TrojanDropper:Win64/NeedyMantis and Behavior:Win64/NeedyMantis. Teams on other tooling should look for the DLL names above sitting in unusual ProgramData folders next to legitimate software.
Indicators (defanged):
- C2: corp.tripswithengine[.]com (port 443, URI /library/zip/)
- WinSparkle.dll loader (SHA-256): e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e
- WinSparkle archive (SHA-256): 9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef
- Older libcurl archive (SHA-256): c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77
- Hard-coded user agent: firefox/21.0
None of NeedyMantis's techniques is exotic on its own. Stacked together behind familiar software names and deployed only against chosen targets, they add up to a tool built for patience rather than speed, which is exactly what makes it hard to find.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.