Campaigns
NeedyMantis: Unpacking a Post Compromise Malware Family Used in Targeted Operations

NeedyMantis: Unpacking a Post Compromise Malware Family Used in Targeted Operations Threat Campaign

NeedyMantisStorm-3069post-compromiseDLL sideloadingmodular malware
Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware family deployed in targeted intrusions affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. The malware is written in C++ and x64 shellcode and uses a multi-stage loader architecture, custom encrypted file archives, a custom executable file format, and WebSockets-based C2 communications. Activity has been observed since at least October 2025 and aligns with threat actors operating from China, with Storm-3069 identified as one known user.

Indicators of Compromise

corp.tripswithengine.com

Campaign Guidance

Remediation, mitigation, notes, history and related intelligence

REMEDIATION 

DETECTION


Technique ID

Technique Name

Detection Strategy

T1574.002

Hijack Execution Flow: DLL Side-Loading

Not found in current MITRE ATT&CK data.

T1027

Obfuscated Files or Information

Correlates script execution or suspicious parent processes with creation or modification of encoded, compressed, or encrypted file formats (e.g., .zip, .7z, .enc) and abnormal command-line syntax or PowerShell obfuscation. Detects use of gzip, base64, tar, or openssl in scripts or commands that encode/encrypt files after file staging or system enumeration. Monitors use of archive or encryption tools (zip, openssl) tied to user-scripted activity or binaries writing encoded payloads under /Users or /Volumes. Identifies transfer of base64, uuencoded, or high-entropy files over HTTP, FTP, or custom protocols in lateral movement or exfiltration streams. Detects encoded PowerCLI or Base64-encoded payloads staged via datastore uploads or shell access (e.g., ESXi Shell or backdoored VIBs).

T1036.005

Match Legitimate Resource Name or Location

Detects processes or binaries executed from trusted directories (e.g., System32) or using trusted names (e.g., svchost.exe) where the metadata, hash, or parent process does not align with legitimate activity patterns. Detects renamed binaries or scripts placed into trusted paths like /usr/bin or /lib with mismatched metadata or unexpected creation/modification times. Detects binaries or launch daemons in /System/Library or /Applications with mismatched bundle names, unexpected metadata, or improper installation origin. Detects malicious containers or pods using names, labels, or namespaces that mimic legitimate workloads; also checks for image layer mismatches and unauthorized resource deployments. Detects VIBs, scripts, or binaries placed into directories like /bin or /etc/vmware with names mimicking standard ESXi components. Also monitors unauthorized creation of services.

T1071.001

Web Protocols

Detects unexpected or high-volume HTTP/S/WebSocket communication from suspicious processes (e.g., PowerShell, rundll32) using uncommon user agents or mimicking browser traffic to unusual domains or IPs. Detects curl, wget, Python requests, or custom HTTP clients communicating over non-standard ports, with repetitive or beacon-like patterns or POST-heavy behavior to rare domains. Detects applications such as Automator, AppleScript, or LaunchDaemons invoking HTTP/S traffic to non-standard domains or using suspicious headers (e.g., Base64 in URIs or cookie fields). Detects HTTP or HTTPS communication initiated by shell-based scripts or management daemons, especially those reaching public IPs over ports 80/443 using embedded curl or wget. Detects Web protocol misuse such as encoded HTTP headers, WebSocket upgrade requests with abnormal payloads, or TLS handshake anomalies suggesting embedded C2 channels.

T1132.001

Standard Encoding

Process invokes a standard encoder (e.g., PowerShell -enc, certutil -encode, base64 via .NET/Invoke-Expression) or emits long Base64/hex literals → shortly followed by outbound network egress with high bytes_out:bytes_in ratio or HTTP headers/payloads containing Base64/MIME blocks. Shell/utility (base64, xxd -p, od, openssl enc -base64, python/perl base64 libraries) encodes data → subsequent outbound connections (curl/wget/bash TCP, socat, python requests) with high asymmetry or Base64/MIME blobs in HTTP/DNS payloads. Processes use base64/xxd/openssl/python Objective‑C APIs to encode data (seen in EndpointSecurity exec events or Unified Logs) → quick outbound connections with large bytes_out or HTTP POSTs carrying Base64/MIME bodies. ESXi shell (BusyBox) or VMware utilities (openssl, python if present) used to Base64/hex encode data from datastore or config files → followed by abnormal egress from the host (NSX/flow logs) with asymmetric bytes_out or HTTPS posts to non-management endpoints.

T1573.001

Symmetric Cryptography

Processes that typically do not perform cryptographic operations loading symmetric encryption libraries (e.g., bcryptprimitives.dll, aes.dll), then initiating outbound connections with high-entropy payloads. Defender correlates process creation, DLL load, and anomalous encrypted traffic patterns. Unexpected processes (e.g., bash, python, custom binaries) dynamically loading libcrypto or performing AES/RC4 encryption operations, then initiating outbound sessions with abnormal byte entropy or asymmetric traffic patterns. Launchd jobs or user processes invoking symmetric crypto APIs from the Security framework and generating outbound connections carrying randomized payloads inconsistent with normal TLS patterns. ESXi daemons (hostd, vpxa) unexpectedly using symmetric encryption routines for external connections. Defender identifies logs of service traffic with encrypted payloads inconsistent with VMware management baselines. Flows showing encrypted payloads with high entropy not matching TLS handshake patterns, particularly when occurring on non-standard ports. Defender observes NetFlow/IPFIX byte distribution anomalies or IDS/IPS detecting symmetric encryption patterns without associated key exchange.

T1106

Native API

Unusual or suspicious processes loading critical native API DLLs (e.g., ntdll.dll, kernel32.dll) followed by direct syscall behavior, memory manipulation, or hollowing. Userland processes invoking syscall-heavy libraries (libc, glibc) followed by fork, mmap, or ptrace behavior commonly associated with code injection or memory manipulation. Execution of processes that link to CoreServices or Foundation APIs followed by creation of memory regions, code execution, or abnormal library injection.

T1057

Process Discovery

Identifies adversary behavior that launches commands or invokes APIs to enumerate active processes (e.g., tasklist.exe, Get-Process, or CreateToolhelp32Snapshot). Detects execution combined with parent process lineage, network session context, or remote origin. Detects execution of common process enumeration utilities (e.g., ps, top, htop) or access to /proc with suspicious ancestry. Correlates command usage with interactive shell context and user role. Monitors execution of ps, top, or launchctl with unusual parent processes or from terminal scripts. Also detects AppleScript-based process listing or system_profiler SPApplicationsDataType misuse. Detects process enumeration using esxcli system process list or ps on ESXi shell or via unauthorized SSH sessions. Correlates with interactive sessions and abnormal user roles. Monitors CLI-based execution of show process or equivalent on routers/switches. Correlates unusual device access, unauthorized roles, or config mode changes.

T1083

File and Directory Discovery

Execution of file enumeration commands (e.g., 'dir', 'tree') from non-standard processes or unusual user contexts, followed by recursive directory traversal or access to sensitive locations. Use of file enumeration commands (e.g., 'ls', 'find', 'locate') executed by suspicious users or scripts accessing broad file hierarchies or restricted directories. Execution of file or directory discovery commands (e.g., 'ls', 'find') from terminal or script-based tooling, especially outside normal user workflows. Execution of esxcli commands to enumerate datastore, configuration files, or directory structures by unauthorized or remote users. Execution of file discovery commands (e.g., 'dir', 'show flash', 'nvram:') from CLI interfaces, especially by unauthorized users or from abnormal source IPs.

T1570

Lateral Tool Transfer

Correlate suspicious file transfers over SMB or Admin$ shares with process creation events (e.g., cmd.exe, powershell.exe, certutil.exe) that do not align with normal administrative behavior. Detect remote file writes followed by execution of transferred binaries. Monitor scp, rsync, curl, sftp, or ftp processes initiating transfers to internal systems combined with file creation events in unusual directories. Correlate transfer activity with subsequent execution of those binaries. Detect anomalous use of scp, rsync, curl, or third-party sync apps transferring executables into user directories. Correlate new file creation with immediate execution events. Identify lateral transfer via datastore file uploads or internal scp/ssh sessions that result in new VMX/VMDK or script files. Correlate transfer with VM execution or datastore modification.

Observed Countries250

AD (526)
AE (926)
AF (657)
AG (918)
AI (119)
AL (220)
AM (779)
AO (641)
AQ (179)
AR (883)
AS (779)
AT (27)
AU (869)
AW (643)
AX (845)
AZ (580)
BA (200)
BB (922)
BD (517)
BE (694)
BF (714)
BG (112)
BH (798)
BI (787)
BJ (737)
BL (935)
BM (342)
BN (288)
BO (36)
BQ (995)
BR (151)
BS (646)
BT (710)
BV (591)
BW (535)
BY (182)
BZ (17)
CA (365)
CC (567)
CD (729)
CF (318)
CG (903)
CH (310)
CI (816)
CK (470)
CL (64)
CM (956)
CN (284)
CO (494)
CR (806)
CU (678)
CV (857)
CW (536)
CX (790)
CY (648)
CZ (697)
DE (759)
DJ (248)
DK (31)
DM (960)
DO (873)
DZ (458)
EC (832)
EE (39)
EG (89)
EH (315)
ER (82)
ES (262)
ET (287)
FI (121)
FJ (547)
FK (150)
FM (934)
FO (650)
FR (403)
GA (240)
GB (264)
GD (854)
GE (282)
GF (779)
GG (452)
GH (31)
GI (976)
GL (534)
GM (485)
GN (152)
GP (19)
GQ (418)
GR (611)
GS (133)
GT (20)
GU (185)
GW (451)
GY (263)
HK (453)
HM (928)
HN (479)
HR (800)
HT (941)
HU (317)
ID (776)
IE (669)
IL (767)
IM (410)
IN (834)
IO (392)
IQ (783)
IR (584)
IS (423)
IT (825)
JE (575)
JM (77)
JO (980)
JP (893)
KE (937)
KG (29)
KH (570)
KI (221)
KM (216)
KN (52)
KP (966)
KR (935)
KW (681)
KY (727)
KZ (713)
LA (293)
LB (442)
LC (574)
LI (263)
LK (306)
LR (91)
LS (502)
LT (409)
LU (864)
LV (505)
LY (517)
MA (896)
MC (669)
MD (259)
ME (351)
MF (541)
MG (838)
MH (842)
MK (970)
ML (841)
MM (321)
MN (581)
MO (43)
MP (837)
MQ (311)
MR (587)
MS (916)
MT (572)
MU (837)
MV (549)
MW (816)
MX (438)
MY (622)
MZ (259)
NA (314)
NC (187)
NE (798)
NF (781)
NG (10)
NI (316)
NL (424)
NO (203)
NP (31)
NR (794)
NU (831)
NZ (783)
OM (482)
PA (376)
PE (344)
PF (85)
PG (921)
PH (24)
PK (286)
PL (919)
PM (417)
PN (744)
PR (682)
PS (101)
PT (721)
PW (528)
PY (964)
QA (784)
RE (933)
RO (791)
RS (147)
RU (494)
RW (952)
SA (577)
SB (484)
SC (952)
SD (271)
SE (710)
SG (849)
SH (761)
SI (609)
SJ (899)
SK (192)
SL (723)
SM (202)
SN (561)
SO (137)
SR (55)
SS (181)
ST (768)
SV (819)
SX (188)
SY (58)
SZ (316)
TC (361)
TD (881)
TF (517)
TG (244)
TH (629)
TJ (14)
TK (540)
TL (950)
TM (582)
TN (374)
TO (872)
TR (733)
TT (341)
TV (83)
TW (129)
TZ (652)
UA (935)
UG (774)
UM (486)
US (715)
UY (312)
UZ (374)
VA (626)
VC (775)
VE (917)
VG (530)
VI (546)
VN (338)
VU (593)
WF (843)
WS (524)
XK (468)
YE (671)
YT (600)
ZA (358)
ZM (185)
ZW (155)