NeedyMantis: The Patient Predator Hiding in Plain Sight
Storm-3069 uses the NeedyMantis modular backdoor, delivered by DLL sideloading inside legitimate software bundles, to keep long-term access to breached Windows networks.
Summary
- First seen
- October 2025
- Targeted regions
- Worldwide
- Targeted platform
- Windows
- Targeted industries
- Telecommunications, education, healthcare, nonprofits, government
- Threat actor
- Storm-3069
- Malware
- NeedyMantis
NeedyMantis is a modular, post-compromise backdoor used by the China-based actor Storm-3069 to maintain long-term access to already breached networks in telecommunications, education, healthcare, nonprofit, and government. It is delivered through DLL sideloading inside bundles of legitimate software such as Poedit, curl, Vim, and TightVNC, unpacks through layered loaders, custom encrypted archives, and a custom executable format, and then talks to its operators over HTTPS, which upgrades to an RC4-protected WebSockets channel through which new modules can be loaded on demand.
Attack Details
NeedyMantis is a stealthy modular malware used by Storm-3069, a China-based threat actor, to stay hidden inside networks it has already broken into. It is not used to break in. Instead, the attackers install it after they gain access so they can keep coming back, quietly watch the environment, and add new capabilities whenever they need them. Active since at least October 2025, with a newer version appearing in May 2026, it hides inside trusted software and talks to its operators through ordinary-looking web traffic, which makes it hard to spot.
The malware was discovered during investigations into the DAEMON Tools supply chain compromise, but there is no evidence that NeedyMantis itself was spread through that incident. Storm-3069 has not been tied to any known Chinese state-sponsored group, and a possible link to UNC6863, a suspected China-nexus cluster behind the DAEMON Tools activity, remains unconfirmed.
The attackers deliver NeedyMantis through DLL sideloading. They place a trusted program such as Poedit, curl, Vim, or TightVNC next to a malicious DLL named after a file that program expects to load, along with an encrypted archive. When the trusted program starts, it loads the malicious DLL without raising suspicion. To reach more machines, the operators used the Impacket toolkit to copy this bundle from a network share and run it on other devices.
Once running, the malware unpacks itself in stages. The first loader checks whether it is being analyzed, then decrypts the archive, which mixes the real payload with harmless 7-Zip, Sysinternals, and Windows files to blend in. Inside is a second loader disguised as a PowerShell script that is actually shellcode, plus a configuration file and a communications module named after real Windows libraries. The final component is stored in a custom file format that standard analysis tools cannot easily read. An older version stayed on infected systems by installing itself as a Windows service.
After setup, NeedyMantis contacts its command server over HTTPS using an outdated Firefox user agent and sends back a basic host profile: computer name, username, running processes, and the contents of the Program Files folder. The connection then switches to an encrypted WebSockets channel, through which operators can load or remove extra modules on demand.
Recommendations
-
01Block the NeedyMantis C2 HostBlock and alert on outbound traffic to
corp[.]tripswithengine[.]comat DNS, proxy, and firewall layers, and review historical DNS and proxy logs for prior connections to identify already compromised hosts. -
02Hunt for Sideloaded DLLs in Unusual LocationsSearch endpoints for the listed loader paths and for
WinSparkle.dll,libcurl.dll,vim64.dll,dbghelp.dll,jli.dll, andnvml.dllsitting beside Poedit, curl, Vim, or TightVNC binaries in ProgramData or other writable folders, and validate any copy that is unsigned, recently written, or accompanied by an unexplained archive file. -
03Validate Filename-Based Indicators Before BlockingSeveral NeedyMantis components reuse names of legitimate Windows libraries such as
dbghelp.dll,dnsapi.dll, andws2_32.dll, so match on path, hash, and signer rather than filename alone to avoid disrupting legitimate software. -
04Detect the firefox/21.0 User-Agent and WebSockets UpgradesCreate network and proxy rules for the outdated
firefox/21.0User-Agent and for HTTPS sessions that upgrade to WebSockets from non-browser processes such as Poedit.exe, curl, Vim, or TightVNC. -
05Monitor for Impacket-Driven Lateral Tool TransferAlert on Impacket execution patterns and on legitimate application binaries, DLLs, and archive files being copied from network shares and executed on remote hosts, and restrict administrative share access to approved management systems.
MITRE ATT&CK TTPs
Indicators of Compromise (IoCs)
| Type | Value |
|---|---|
| SHA256 |
e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e
9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef
c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77
|
| Domain | corp[.]tripswithengine[.]com |
| URL | hxxps[:]//corp[.]tripswithengine[.]com[:]443/library/zip/ |
| Filename |
WinSparkle.dll
libcurl.dll
vim64.dll
dbghelp.dll
jli.dll
nvml.dll
encryptbase64.ps1
msvcrt140.dll
300.c
300.s
m.l
|
| File Path |
%ProgramFiles%\Poedit\WinSparkle.dll
%ProgramData%\USOShared\libcurl.dll
%ProgramData%\VIM\vim64.dll
%ProgramData%\TightVNC\VIM\vim64.dll
%ProgramData%\office\dbghelp.dll
%ProgramData%\broadcom\dbghelp.dll
%ProgramData%\Intel\jli.dll
%ProgramFiles%\modifiable\nvml.dll
%ProgramData%\ics\nvml.dll
|
References
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.
