Skip to content
Threat Feed
high advisory

NeedyMantis Modular Malware Framework Analysis

NeedyMantis is a modular, post-compromise malware framework used by threat actors to maintain long-term persistence through DLL sideloading and custom encrypted archives.

Microsoft has disclosed details regarding NeedyMantis, a sophisticated and modular malware framework observed in targeted attacks against government, telecommunications, scientific, manufacturing, and medical sectors. The framework is typically deployed by attackers after initial access is established, serving as a platform for long-term persistence and follow-on operations. NeedyMantis has been active since at least October 2025 and has been associated with activity following the May 2026 Daemon Tools supply chain compromise, though it is used by multiple China-based threat actors. The framework is notable for its modular architecture, which employs custom encrypted file archives, specialized executable file formats, and x64 shellcode to evade traditional security controls. By utilizing a WebSocket-based communication protocol, the framework maintains stealthy command-and-control (C2) operations, allowing operators to dynamically load or unload malicious modules as required by their objectives.

Attack Chain

  1. An attacker establishes initial access to the target network using tools such as the Impacket toolkit.
  2. The attacker uses hands-on-keyboard activity to copy legitimate software, a malicious DLL, and an encrypted file archive from a network share to the targeted device.
  3. The malware abuses DLL sideloading by placing a malicious DLL alongside legitimate software to execute the first-stage loader.
  4. The first-stage loader extracts and executes a second-stage loader from the encrypted file archive.
  5. The second-stage loader decodes and decompresses embedded data, resulting in a minimized PE file formatted with a custom executable structure.
  6. The main malware component initializes a WebSocket-based connection to the C2 server for command receipt and data exfiltration.
  7. The operator dispatches commands to load or unload additional modules to expand functionality and maintain persistence.

Impact

The NeedyMantis framework has been used against diverse high-value targets, including universities, government contractors, telecommunications firms, and intergovernmental organizations across Thailand, Belarus, and Russia. Successful deployment allows attackers to maintain stealthy, long-term access to sensitive networks, conduct follow-on operations, and potentially exfiltrate intellectual property or governmental data. While the full extent of the damage is currently being assessed, the framework's design specifically targets the evasion of detection systems to support extended unauthorized access.

Recommendation

  1. Monitor for the use of the Impacket toolkit within the environment, as this was observed in hands-on-keyboard activity to stage NeedyMantis components.
  2. Implement strict controls on network shares to prevent the unauthorized copying of files and DLLs to sensitive endpoints.
  3. Deploy detection logic for DLL sideloading, specifically looking for common legitimate applications (often used in these attacks) loading unsigned or non-standard DLLs from their own directory.
  4. Hunt for unexpected WebSocket connections originating from non-browser processes or critical servers, as the NeedyMantis C2 traffic utilizes this protocol.
  5. Conduct memory scanning for the execution of minimized or custom-formatted PE files that deviate from standard Windows executable signatures.

Immediate actions

Review endpoint logs for unauthorized use of Impacket tools

SOC 24h

Threat Hunt

Search for processes making external WebSocket connections from unexpected binary paths

T1071.001 high high confidence hunt now

Data: Network connection logs with process context

Mitigations

Tighten access control lists on network shares to prevent unauthorized file distribution

short_term IT Operations

Staging of malware components

Detection coverage 1

Detect Suspicious DLL Sideloading via Process Creation

high

Detects instances where common legitimate applications are launched from unexpected directories, a common indicator of DLL sideloading in the NeedyMantis chain.

sigma tactics: defense_evasion techniques: T1574.002 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →