top of page

The Mantis Inside the Machine: How NeedyMantis Hides in Breached Networks

hace 6 días
3 min de lectura

A mantis survives by becoming part of its environment.

It stays motionless. Camouflaged. Patient.

NeedyMantis brings the same strategy inside compromised networks.

Rather than being described as the mechanism attackers use to break through the perimeter, the malware has been observed maintaining long-term access after attackers are already inside.


Phase 1 — The Mantis Enters an Already Breached Habitat


Microsoft has observed NeedyMantis in a small number of targeted intrusions affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations and government contractors.

Its activity dates back to at least October 2025.

Microsoft discovered the malware while investigating indicators connected to the DAEMON Tools supply-chain compromise and tracks activity associated with that campaign as Storm-3069.

But Microsoft has not observed NeedyMantis itself being distributed through that supply-chain attack, and more than one threat actor may be using the malware.

The mantis, in other words, can appear in different habitats.


Phase 2 — It Camouflages Itself


Once inside, NeedyMantis does what a mantis does best.

It blends in.

The malware has been deployed alongside legitimate applications including Poedit, curl, Vim and TightVNC, while malicious DLLs have also masqueraded as files associated with Microsoft Office, Broadcom, Intel and NVIDIA.

The technique is DLL sideloading.

Attackers place a legitimate executable beside a malicious DLL carrying the name of a library the application expects to load.

The trusted application starts.

But hidden beside it is the mantis.


Phase 3 — The Shell Opens


Once the malicious DLL is loaded, it extracts another stage from an encrypted archive.

That stage then decodes NeedyMantis’ main component.

The malware connects to its command-and-control infrastructure over HTTPS before switching to a WebSocket connection.

Through that channel, operators can load and unload additional modules and exchange data with them.

Microsoft has not confirmed the purpose of those modules.

The insect is hidden inside the computer.

But somebody outside can still tell it when to move.


Phase 4 — It Waits


NeedyMantis is designed around persistence rather than noise.

An older version observed in October 2025 included a persistence module based on Windows services, although Microsoft has not detailed how the newer analyzed version maintains its presence.

That long-term access is what makes the mantis metaphor particularly fitting.

Its advantage is not constant movement.

It is patience.

By hiding alongside legitimate software and maintaining communication with its operators, NeedyMantis can provide a foothold inside an environment that has already been compromised.


Phase 5 — Hunt for the Mantis


Finding something designed to camouflage itself requires looking for the details that do not belong.

Microsoft has published file hashes, malicious paths, a C2 domain and a hard-coded firefox/21.0 user agent, together with hunting queries for Defender XDR and Microsoft Sentinel.

Defenders should also inspect outbound connections to the identified C2 infrastructure and investigate suspicious DLL sideloading behavior.

Microsoft recommends enabling cloud-delivered protection, block at first sight, EDR in block mode, network protection and automatic attack disruption, together with its recommended attack surface reduction rules.

One important caveat: legitimate files can occupy some of the same paths. For example, WinSparkle.dll is normally part of Poedit, so a filename or path alone does not establish an infection. Hashes and surrounding behavior matter.


The Insect You Never Saw Enter


NeedyMantis illustrates a different side of network compromise.

The dramatic moment may have happened earlier, when the attackers first gained access.

After that, the objective changes.

Hide.

Blend in.

Establish communication.

Stay available.

Wait.

Because sometimes the most dangerous presence inside a compromised network is not malware making noise.

It is the mantis sitting perfectly still inside the machine.


The Hacker News


 
 
 

2 comentarios


rozzoadel88
hace 6 días

The description of NeedyMantis as a silent, camouflaged threat perfectly highlights the evolving challenge in cybersecurity. Its reliance on DLL sideloading and blending with legitimate applications makes detection incredibly difficult, especially since it's designed for long-term presence rather than immediate impact. This truly feels like a game of cat and mouse, or perhaps more accurately, like trying to find a hidden imposter in a town of salem.

Me gusta

chained88tog
hace 6 días

The "mantis" metaphor perfectly illustrates the insidious nature of NeedyMantis, prioritizing stealth and long-term access over noisy initial attacks. It's unsettling how effectively it blends into legitimate software using DLL sideloading, emphasizing that detection isn't just about spotting individual threats but understanding how seemingly benign elements can be chained together for malicious purposes. This makes robust behavioral analysis and continuous monitoring absolutely critical for defenders.

Me gusta
bottom of page