Microsoft has published an analysis of NeedyMantis, a modular post-compromise malware family used to maintain access in targeted intrusions. Microsoft observed it at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors, with activity dating to at least October 2025.
The malware commonly uses DLL sideloading: a legitimate program loads a malicious DLL alongside an encrypted archive that contains the next stage. Microsoft reports that actors used binaries associated with Poedit, curl, Vim, and TightVNC, while the malware also impersonated DLLs associated with common software vendors. It establishes HTTPS command-and-control and then moves to WebSocket communications.
Hunting priorities
Defenders should use Microsoft’s published file hashes, C2 domain, paths, user-agent indicator, and Defender XDR/Sentinel hunting queries. A file path alone is not proof of infection; for example, WinSparkle.dll can be legitimate in a Poedit installation. Validate hashes and investigate suspicious outbound traffic together with endpoint telemetry.
Source: Microsoft Security Blog; The Hacker News.
