CyberSecurityNews

Microsoft Finds New Malware Used to Maintain Secret Access Inside Target Networks


Microsoft Threat Intelligence has uncovered NeedyMantis, a modular post-compromise malware framework designed to preserve covert access inside already-breached networks.

The malware has appeared in a small number of highly targeted intrusions involving telecommunications providers, universities, medical nonprofits, intergovernmental bodies, and government contractors.

Activity dates to at least October 2025, suggesting operators have quietly used the framework for long-term espionage-oriented access rather than indiscriminate cybercrime.

Microsoft new malware secret network access

According to research published by Microsoft, researchers discovered NeedyMantis while pivoting from indicators linked to the DAEMON Tools supply-chain compromise, tracked by Microsoft as Storm-3069.

Kaspersky previously found that attackers had inserted malicious code into certain DAEMON Tools Lite binaries distributed through official installers.

Microsoft assesses Storm-3069 as China-based activity but has not attributed it to a specific Chinese state-sponsored group. Separate NeedyMantis infections also suggest that more than one operator may possess the malware.

Importantly, Microsoft has not seen NeedyMantis itself delivered through the compromised DAEMON Tools supply chain. Available evidence indicates attackers deploy it after obtaining initial access, meaning the entry vector can differ between victims.

In one incident, an operator used the Impacket toolkit to copy legitimate software, a malicious DLL, and an encrypted archive from a network share before executing the package on a selected device.

The infection chain relies on DLL sideloading, allowing a legitimate application to load a malicious library masquerading as a required component. Operators have abused Poedit, curl, Vim, and TightVNC packages while disguising files as Microsoft Office, Broadcom, Intel, or NVIDIA libraries.

The first-stage loader extracts a second-stage payload from a custom archive whose offsets, XOR keys, compression, and filenames change between samples, complicating static detection and automated analysis.

WinSparkle custom archive unpacking metadata (Image Source: Microsoft)

In Microsoft’s examined sample, a rogue WinSparkle.dll replaced Poedit’s legitimate update component. The loader concealed API names and constants using obfuscated stack strings, dynamically resolved Windows functions, and checked ProcessDebugFlags and ThreadHideFromDebugger to frustrate analysts. It then extracted encryptbase64.ps1.

Despite its PowerShell-looking extension, that file contained x64 shellcode, which decoded and decompressed NeedyMantis’ main component stored in a minimized, custom executable format.

Deobfuscation routine for API strings
Deobfuscation routine for API strings (Image Source: Microsoft)

Once active, the main component manages command-and-control traffic and downloadable modules. Its configuration pointed to corp.tripswithengine[.]com over port 443 and the URI /library/zip/.

An initial HTTPS request places compressed, Base64-encoded system details inside a Set-Cookie header, including the computer name, username, running process, parent process, installed files, and process list.

Communication then upgrades to WebSockets and uses a custom binary protocol with XOR encoding, compression, and optional RC4 encryption.

Deobfuscation logic for sleep constant value
Deobfuscation logic for sleep constant value (Image Source: Microsoft)

NeedyMantis can receive commands to load or unload modules, dispatch data, and disable active flags, while sending identification and keepalive messages.

Microsoft has not confirmed the capabilities of downloaded modules, but the architecture lets operators add functionality without replacing the core implant, an effective design for persistent, adaptable access.

The selective victim profile makes the campaign significant for security teams protecting sensitive research, public services, and communications infrastructure.

Because NeedyMantis appears only after compromise, finding it should trigger an incident investigation covering credential theft, lateral movement, persistence mechanisms, staging servers, and attacker activity preceding deployment.

Defenders should immediately hunt for outbound connections to corp.tripswithengine[.]com, unexpected DLL loads, suspicious decoding, Impacket execution, and NeedyMantis files placed beside legitimate applications.

Microsoft recommends cloud-delivered protection, block-at-first-sight, network protection, EDR in block mode, automatic attack disruption, and attack-surface-reduction rules blocking untrusted executables and obfuscated scripts.

Defender detections include TrojanDropper:Win64/NeedyMantis, Behavior:Win64/NeedyMantis, and alerts for suspicious sideloading or Impacket activity.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link