CYBERSECURITYTRACKER
TRACKING
Permanent story citation

NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8712

As cited

Copy frozen at (site build).

threat intel

NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware family deployed after threat actors establish initial access to target environments. The malware, active since at least October 2025, uses DLL sideloading with spoofed legitimate software, custom encrypted archives, and multiple loader stages to maintain persistence and support follow-on operations. Associated activity aligns with China-based threat actors and has targeted telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors.

Why it matters: Organizations in telecommunications, higher education, healthcare, government, and intergovernmental sectors should hunt for DLL sideloading activity using masqueraded software components (Poedit, curl, Vim, TightVNC, Microsoft Office, Broadcom, Intel, NVIDIA) and monitor for outbound connections to corp.tripswithengine.com, as NeedyMantis indicates an attacker already has network access and is establishing long-term persistence.

VendorsMicrosoftGoogleVMware
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary