As cited
Copy frozen at (site build).
threat intel
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware family deployed after threat actors establish initial access to target environments. The malware, active since at least October 2025, uses DLL sideloading with spoofed legitimate software, custom encrypted archives, and multiple loader stages to maintain persistence and support follow-on operations. Associated activity aligns with China-based threat actors and has targeted telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors.
Why it matters: Organizations in telecommunications, higher education, healthcare, government, and intergovernmental sectors should hunt for DLL sideloading activity using masqueraded software components (Poedit, curl, Vim, TightVNC, Microsoft Office, Broadcom, Intel, NVIDIA) and monitor for outbound connections to corp.tripswithengine.com, as NeedyMantis indicates an attacker already has network access and is establishing long-term persistence.
- Source published
- First seen by Cybersecurity Tracker