# What Microsoft found
# How NeedyMantis is used NeedyMantis is a post-compromise toolset. Microsoft's analysis indicates attackers first gain access to an environment by other means, then install NeedyMantis to keep long-term access and enable follow-on operations. The framework contains multiple components written in C++ and x64 shellcode. The malware deploys anti-analysis techniques to evade detection and hinder defensive analysis.
Delivery and deployment are hands-on. Microsoft observed operators installing components directly on compromised systems and packaging malicious files alongside legitimate software downloads to disguise activity. The installation chain frequently uses DLL side-loading as the first-stage loader.
# Delivery techniques observed
- Legitimate open-source software abused as cover: Poedit, curl, Vim and TightVNC were seen packaged with NeedyMantis artifacts.
- Fake vendor DLLs used as decoys: components posing as Microsoft Office, Broadcom, Intel and NVIDIA DLLs have been observed.
- Multi-stage loaders: the initial loader is followed by a second-stage loader to embed the framework, then a final stage establishes command-and-control (C2) connectivity for persistence and data exfiltration.
# Link to Storm-3069 and supply chain context Microsoft identified Storm-3069 as one operator associated with NeedyMantis activity. Storm-3069 has prior linkage to a supply chain compromise involving DAEMON Tools, but Microsoft did not find evidence that NeedyMantis itself was distributed via that supply chain compromise. Microsoft notes supply chain activity remains a possible means for actors to gain the necessary access to deploy the malware, but it did not confirm supply chain distribution of NeedyMantis.
# Operational impact and defender actions NeedyMantis provides attackers with persistent remote access, the ability to exfiltrate data, and to deploy additional components. The malware's anti-analysis features and use of legitimate software as a delivery vehicle increase the chance of prolonged compromise if not detected.
Microsoft published indicators and hunting queries defenders can use. The company also recommended configuration and product-level mitigations focused on rapid detection and blocking.
# Microsoft mitigation recommendations
- Turn on cloud-delivered protection and enable block-at-first-sight to rapidly identify and block new and unknown malware variants.
- Run Endpoint Detection and Response (EDR) in block mode so Microsoft Defender for Endpoint can block malicious artifacts.
- Enable network protection in Microsoft Defender for Endpoint.
- Configure automatic attack disruption in Microsoft Defender XDR to interrupt attacker activity.
These measures are presented as immediate controls defenders can enable within Microsoft security products to reduce the chance of successful deployment and persistence of NeedyMantis.
# Bottom line NeedyMantis is a stealthy, multi-component post-compromise framework that attackers use to remain hidden and maintain long-term access. Delivery via DLL side-loading bundled with legitimate software and use of anti-analysis techniques make detection harder. Organizations should use the published indicators and consider the listed product configurations to reduce exposure and disrupt active intrusions.