Skip to content
Security & Trust

Microsoft: NeedyMantis malware hides behind legitimate software after intrusion

In a limited number of targeted operations, Microsoft says, post-compromise malware hides beside trusted software

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Microsoft: NeedyMantis malware hides behind legitimate software after intrusion

Photo: Edward Jenner / Pexels

Key finding

Earliest observed NeedyMantis activity: At least October 2025 (Source: Microsoft Security blog (September 28, 2026))

The question after the breach

Perimeter-focused controls ask one question: did something hostile get in? NeedyMantis is a case study in the question that follows. Microsoft Threat Intelligence classes it as a modular malware family that tends to appear late in an intrusion, once someone is already inside the environment. From what Microsoft has observed, the purpose is to hold a foothold for the long haul and to enable whatever the operators do next.

The lesson here is that the difficulty did not disappear at the perimeter. It relocated inside it, to a place where the malicious file is built to look like something your own software inventory would accept.

At least October 2025
Earliest observed NeedyMantis activity
Source: Microsoft Security blog (September 28, 2026)

A disguise packaged alongside trusted software

The malware itself is not made of legitimate tools. Microsoft describes components written in C++ and x64 shellcode. What makes it hard to spot is the packaging. In Microsoft's account, an infection starts with two pieces: a loader and an encrypted archive, both placed next to a genuine application. The loader passes itself off as a DLL that the application needs, and it runs through DLL sideloading. In the sample Microsoft analyzed, it stood in for the WinSparkle update component of the Poedit translation software.

The open-source programs Microsoft lists as abused include Poedit, curl, Vim and TightVNC. Other samples imitate DLL components from Microsoft Office, Broadcom, Intel and NVIDIA. The disguise continues in later stages. A second-stage file with a .ps1 PowerShell extension holds x64 shellcode rather than a script. Configuration and communications files borrow the names of Windows networking libraries.

For an executive, the point is practical. A control that asks whether a file is a known-good application will see the legitimate application. The malicious part is the piece sitting next to it.

11
Files in the analyzed sample's archive
Source: Microsoft Security blog (September 28, 2026)
4
Files in an older version's archive
Source: Microsoft Security blog (September 28, 2026)

These are two samples Microsoft analyzed, not a measured trend. They do show that the archives vary. Microsoft also says the archive's offsets, XOR keys and values change from sample to sample. Our reading is that a signature built around one sample's structure has limited reach against the next.

How it arrives, and who was affected

One incident Microsoft examined involved an operator working live at the keyboard with the Impacket toolkit. The operator pulled the genuine application, the rogue DLL and the archive off a network share and launched them on a target machine. This happened after the actor already had access. Microsoft adds that the way in may differ from one intrusion to another.

Microsoft's discovery came from pivoting off indicators tied to the DAEMON Tools supply chain compromise, an incident Kaspersky had already reported. Microsoft uses the designator Storm-3069 for activity associated with that compromise, and it is one known user of NeedyMantis. Even so, Microsoft has not seen NeedyMantis itself delivered through a supply chain compromise.

The intrusions Microsoft has seen touched government contractors, medical nonprofits, intergovernmental organizations, universities and telecommunications firms. Microsoft reads this, together with the limited deployment, as selective rather than broad use. Activity so far aligns with what it associates with China-based threat actors. Two questions stay open in its account: whether one operator or several are behind the malware, and whether Storm-3069 is a Chinese nation-state actor, which Microsoft has not asserted.

What the analysis does not yet tell us

The main component communicates with its command-and-control server over WebSockets, following an initial HTTPS request. It has a small set of commands, including loading and unloading additional modules. Microsoft says those commands show NeedyMantis can extend its functionality, but the capabilities of the modules remain unconfirmed. Leaders should read that as a limit of the evidence. The reported facts do not say what those modules do, and this story does not guess.

Questions to put to your team

First, can we tell when a legitimate application loads a DLL that does not belong to it, or one that sits in an unexpected location? Sideloading is the mechanism Microsoft describes, so visibility into it is the direct test.

Second, what would we see if someone copied an application folder from a network share and ran it on another device? Microsoft observed exactly this sequence in one incident.

Third, do our detections rely on file names and hashes, or on behavior? Microsoft reports that the archive's offsets and XOR keys change from sample to sample.

Fourth, have we reviewed Microsoft's published indicators, Defender detections and mitigation guidance against our environment? These are in the original Microsoft post. If your sector overlaps with the victim list, that review is a reasonable place to start.

The point to keep: NeedyMantis, which arrives after the breach, is packaged to look like software you already trust, so defenders have to judge what that software does rather than what it is called.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Microsoft Security.

Share this insight