Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Microsoft Warns of New Malware Granting Attackers Persistent Access
September 28, 2026
Florida AG Sues OpenAI to Restrict ChatGPT Over AI Safety Risks
September 28, 2026
AI-Powered Attack Tool Exposed: Threat Actors Left Control Panel Unsecured
September 28, 2026
Home/CyberSecurity News/Microsoft Warns of New Malware Granting Attackers Persistent Access
CyberSecurity News

Microsoft Warns of New Malware Granting Attackers Persistent Access

Key Takeaways Microsoft has identified a new sophisticated malware, NeedyMantis, designed for persistent access. The malware employs a multi-stage infection chain, using custom archives, obfuscation,...

Jennifer sherman
Jennifer sherman
September 28, 2026 3 Min Read
3 0

Key Takeaways

  • Microsoft has identified a new sophisticated malware, NeedyMantis, designed for persistent access.
  • The malware employs a multi-stage infection chain, using custom archives, obfuscation, and anti-analysis techniques.
  • NeedyMantis establishes command-and-control (C2) communication via WebSockets, using a custom binary protocol with XOR encoding, compression, and optional RC4 encryption.
  • While specific module capabilities are unconfirmed, its modular architecture allows attackers to extend functionality without redeploying the core implant.
  • Organizations with sensitive research, public services, or communications infrastructure are particularly at risk.

Microsoft Details NeedyMantis Malware: A Stealthy Threat for Persistent Access

Microsoft has issued a warning regarding a newly discovered malware variant, dubbed NeedyMantis, which facilitates persistent access for attackers. This sophisticated threat leverages a multi-stage loading process, intricate obfuscation, and anti-analysis measures to maintain stealth and adaptability.

Table Of Content

  • Key Takeaways
  • Microsoft Details NeedyMantis Malware: A Stealthy Threat for Persistent Access
  • Initial Infection and Evasion Tactics
  • Command and Control (C2) Communication
  • Modular Design and Threat Profile
  • What You Should Do

Initial Infection and Evasion Tactics

The infection begins with a first-stage loader responsible for extracting a subsequent payload from a unique custom archive. This archive’s structure, including offsets, XOR keys, compression methods, and filenames, varies significantly between samples. This dynamic customization presents a considerable challenge for static detection tools and automated analysis systems, making it difficult to identify consistently.

In one sample analyzed by Microsoft, a malicious WinSparkle.dll file was found replacing the legitimate update component within the Poedit application. The loader itself utilizes several techniques to evade detection and analysis. It obfuscates API names and constants through stack strings, dynamically resolves Windows functions, and actively checks for debugger presence using ProcessDebugFlags and ThreadHideFromDebugger. Following these evasive maneuvers, it proceeds to extract a file named encryptbase64.ps1.

Despite its PowerShell file extension, encryptbase64.ps1 contains x64 shellcode. This shellcode is responsible for decoding and decompressing the primary component of NeedyMantis, which is stored in a highly minimized, custom executable format. This additional layer of disguise further complicates detection efforts.

Command and Control (C2) Communication

Once activated, the core NeedyMantis component takes control of command-and-control (C2) traffic and manages downloadable modules. Microsoft’s analysis revealed that the malware’s configuration points to the domain corp.tripswithengine[.]com over port 443, utilizing the URI /library/zip/ for communication.

The initial phase of communication involves an HTTPS request. During this exchange, compressed, Base64-encoded system details are embedded within a Set-Cookie header. These details encompass critical information such as the computer name, username, currently running processes, parent processes, installed files, and a comprehensive list of all active processes.

After this initial data exfiltration, the communication protocol is upgraded to WebSockets. This WebSocket connection then employs a custom binary protocol that incorporates XOR encoding, compression, and optional RC4 encryption, ensuring a high level of stealth and data integrity for C2 operations.

Modular Design and Threat Profile

NeedyMantis is designed to receive various commands from its operators, including instructions to load or unload modules, dispatch collected data, and disable active flags. Concurrently, it sends identification and keepalive messages back to the C2 server. While Microsoft has not yet confirmed the specific capabilities of the downloadable modules, the malware’s modular architecture is a significant concern. This design allows attackers to introduce new functionalities and adapt to evolving environments without needing to replace the core implant, making it an exceptionally effective tool for persistent and flexible access.

The targeted nature of NeedyMantis makes this campaign particularly relevant for security teams safeguarding sensitive research, critical public services, and vital communications infrastructure. Given that NeedyMantis is typically deployed only after an initial compromise, its discovery should immediately trigger a comprehensive incident investigation. This investigation must span potential credential theft, lateral movement within the network, the identification of persistence mechanisms, the analysis of staging servers, and a thorough review of attacker activities preceding the malware’s deployment.

What You Should Do

  • Actively hunt for outbound network connections to the domain corp.tripswithengine[.]com.
  • Monitor for unexpected DLL loads and suspicious decoding activities on your systems.
  • Investigate any instances of Impacket execution, which could indicate lateral movement by attackers.
  • Search for NeedyMantis files positioned alongside legitimate applications, a common tactic for sideloading.
  • Enable cloud-delivered protection, block-at-first-sight features, and network protection in Microsoft Defender.
  • Ensure Endpoint Detection and Response (EDR) is operating in block mode and leverage automatic attack disruption capabilities.
  • Implement attack surface reduction rules to block untrusted executables and obfuscated scripts.
  • Be aware of Microsoft Defender detections, including TrojanDropper:Win64/NeedyMantis, Behavior:Win64/NeedyMantis, and alerts for suspicious sideloading or Impacket activity.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarePatchSecurity

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Florida AG Sues OpenAI to Restrict ChatGPT Over AI Safety Risks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Bitget Suffers $387.5M Loss in Backend Breach, DPRK-Linked Launderers Implicated
September 28, 2026
OpenCode AI Coding Agent Flaw Lets Malicious Websites Execute Code
September 28, 2026
ShinyHunters Exploits Critical Oracle PeopleSoft CVE-2024-21095 to Deploy Web Shells
September 28, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us