NeedyMantis Hides Its Next Stage Behind Familiar DLL Names

Brendan Smith
Brendan Smith - Cybersecurity Analyst
6 Min Read
A DLL-shaped facade opens to reveal another file hidden inside
NeedyMantis gives malicious components familiar-looking filenames.

A legitimate translation editor can start normally while a replacement library beside it opens an attacker’s next stage. That is one of the disguises Microsoft describes in its September 28 report on NeedyMantis, malware used to sustain access after an intruder has already entered a network. In the analyzed Poedit package, a file named encryptbase64.ps1 was not a PowerShell script at all: it held x64 machine code.

Microsoft has seen the family in a limited number of targeted intrusions involving telecoms, universities, medical nonprofits, intergovernmental organizations and government contractors. The report is new; the observed activity reaches back to at least October 2025. It does not establish that ordinary Poedit, curl, Vim or TightVNC downloads are infected.

Three files arrive after the break-in

In one incident, an operator already inside the environment used Impacket to copy a legitimate application, a malicious DLL and an archive from a network share to a target device, then execute the application. The legitimate program became the entry point for the planted library. This is DLL sideloading: the executable’s familiar identity says little about the neighboring code it loads.

In the Poedit sample, the replacement was WinSparkle.dll, impersonating the application’s updater component. Beside it sat WinSparkle, an archive with no extension. The first loader’s job was to retrieve the next stage from that archive. Other observed arrangements used names such as %ProgramData%\USOShared\libcurl.dll and %ProgramData%\VIM\vim64.dll. These are investigation clues in context, not instructions to delete every file sharing a name.

The archive mixes real components with false identities

Microsoft’s unpacked WinSparkle archive contained 11 files. Several were genuine 7-Zip or Sysinternals components; others borrowed names whose contents told a different story. The apparent dnsapi.dll held malware configuration, while ws2_32.dll supplied the communications component. The mix matters: finding a legitimate utility inside the package would not validate its neighbors.

Microsoft archive-unpacking output showing 11 entries and the first three 7-Zip filenames
WinSparkle archive metadata and its first entries, from Microsoft’s analysis. The full archive contained both legitimate and malicious components.

The screenshot shows an entry count of 11 and familiar 7-Zip filenames at the start of the researcher’s archive listing. Microsoft’s analysis of the remaining entries is what identifies the malicious roles. A directory name or extension alone cannot make that distinction.

The next-stage file, encryptbase64.ps1, contained shellcode despite its script extension. It decoded and decompressed the main component, which used a compact custom executable format. Encoded names and changing archive offsets add work for an analyst; they also explain why this infection cannot be understood as one suspicious executable sitting on disk.

A familiar-looking connection carries system details

The main component manages communication and modules. In Microsoft’s analyzed sample, configuration pointed to corp.tripswithengine[.]com on port 443 with the path /library/zip/. The initial HTTPS request carried encoded system information in a Set-Cookie header, including the computer and user names and details about processes and installed-program folders. Communication then switched to WebSockets.

One communications component used the old-looking user-agent firefox/21.0; another implemented the same interface with a different networking library. The main component could load and unload additional modules and pass data to them. Microsoft has not confirmed what those additional modules do. Remote extensibility is supported by the analysis; claims of universal password theft, ransomware deployment or screen recording are not.

What the DAEMON Tools connection does—and does not—show

Microsoft found NeedyMantis while following indicators from the earlier DAEMON Tools compromise. One observed operator, Storm-3069, is associated with that campaign. Microsoft also found activity beyond it and has not established whether all deployments belong to one operator. It assesses China-associated activity, without attributing Storm-3069 to a Chinese nation-state actor.

Crucially, Microsoft has not observed NeedyMantis itself being distributed through a supply-chain compromise. Its report describes what attackers install after obtaining access; it does not identify one common initial entry route for every victim.

Investigate the package, not just the filename

For a suspected managed endpoint, preserve the application, adjacent DLL and extensionless archive as evidence, together with creation times, process ancestry and network logs. Correlate the reported host and user-agent with the executable that made the connection; a string match alone is not a complete diagnosis. Do not browse the defanged command server or execute the sample to check it.

A suspicious non-sensitive file can also be checked with the Gridinsoft Online Virus Scanner, subject to your organization’s rules on uploading files. A file verdict does not reconstruct the earlier intrusion or prove that other components are absent. The decisive question is how the application, its neighboring files and the remote connection fit together.

References

  1. Microsoft Threat Intelligence. “NeedyMantis: Unpacking a post-compromise malware family used in targeted operations.” Microsoft Security Blog, September 28, 2026. Research report and indicators.
Share This Article
Cybersecurity Analyst
Follow:
Brendan Smith has spent over 15 years knee-deep in cybersecurity, chasing down malware from the gritty reverse-engineering of old-school trojans all the way to wrangling full-blown incident responses for small-to-medium businesses that couldn’t afford a full-blown breach. Over at Gridinsoft, he’s the guy piecing together those double-checked guides on nasty stuff like AsyncRAT, a remote access tool used in malware campaigns—helping readers make sense of the threat and work through cleanup without the extra headache.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?