NeedyMantis Modular Malware Framework Analysis
NeedyMantis is a modular, post-compromise malware framework used by threat actors to maintain long-term persistence through DLL sideloading and custom encrypted archives.
Microsoft has disclosed details regarding NeedyMantis, a sophisticated and modular malware framework observed in targeted attacks against government, telecommunications, scientific, manufacturing, and medical sectors. The framework is typically deployed by attackers after initial access is established, serving as a platform for long-term persistence and follow-on operations. NeedyMantis has been active since at least October 2025 and has been associated with activity following the May 2026 Daemon Tools supply chain compromise, though it is used by multiple China-based threat actors. The framework is notable for its modular architecture, which employs custom encrypted file archives, specialized executable file formats, and x64 shellcode to evade traditional security controls. By utilizing a WebSocket-based communication protocol, the framework maintains stealthy command-and-control (C2) operations, allowing operators to dynamically load or unload malicious modules as required by their objectives.
Attack Chain
- An attacker establishes initial access to the target network using tools such as the Impacket toolkit.
- The attacker uses hands-on-keyboard activity to copy legitimate software, a malicious DLL, and an encrypted file archive from a network share to the targeted device.
- The malware abuses DLL sideloading by placing a malicious DLL alongside legitimate software to execute the first-stage loader.
- The first-stage loader extracts and executes a second-stage loader from the encrypted file archive.
- The second-stage loader decodes and decompresses embedded data, resulting in a minimized PE file formatted with a custom executable structure.
- The main malware component initializes a WebSocket-based connection to the C2 server for command receipt and data exfiltration.
- The operator dispatches commands to load or unload additional modules to expand functionality and maintain persistence.
Impact
The NeedyMantis framework has been used against diverse high-value targets, including universities, government contractors, telecommunications firms, and intergovernmental organizations across Thailand, Belarus, and Russia. Successful deployment allows attackers to maintain stealthy, long-term access to sensitive networks, conduct follow-on operations, and potentially exfiltrate intellectual property or governmental data. While the full extent of the damage is currently being assessed, the framework's design specifically targets the evasion of detection systems to support extended unauthorized access.
Recommendation
- Monitor for the use of the Impacket toolkit within the environment, as this was observed in hands-on-keyboard activity to stage NeedyMantis components.
- Implement strict controls on network shares to prevent the unauthorized copying of files and DLLs to sensitive endpoints.
- Deploy detection logic for DLL sideloading, specifically looking for common legitimate applications (often used in these attacks) loading unsigned or non-standard DLLs from their own directory.
- Hunt for unexpected WebSocket connections originating from non-browser processes or critical servers, as the NeedyMantis C2 traffic utilizes this protocol.
- Conduct memory scanning for the execution of minimized or custom-formatted PE files that deviate from standard Windows executable signatures.
Immediate actions
Review endpoint logs for unauthorized use of Impacket tools
Threat Hunt
Search for processes making external WebSocket connections from unexpected binary paths
Data: Network connection logs with process context
Mitigations
Tighten access control lists on network shares to prevent unauthorized file distribution
Staging of malware components
Detection coverage 1
Detect Suspicious DLL Sideloading via Process Creation
highDetects instances where common legitimate applications are launched from unexpected directories, a common indicator of DLL sideloading in the NeedyMantis chain.
Detection queries are available on the platform. Get full rules →