Microsoft Warns of New Malware Granting Attackers Persistent Access
Key Takeaways Microsoft has identified a new sophisticated malware, NeedyMantis, designed for persistent access. The malware employs a multi-stage infection chain, using custom archives, obfuscation,...
Key Takeaways
- Microsoft has identified a new sophisticated malware, NeedyMantis, designed for persistent access.
- The malware employs a multi-stage infection chain, using custom archives, obfuscation, and anti-analysis techniques.
- NeedyMantis establishes command-and-control (C2) communication via WebSockets, using a custom binary protocol with XOR encoding, compression, and optional RC4 encryption.
- While specific module capabilities are unconfirmed, its modular architecture allows attackers to extend functionality without redeploying the core implant.
- Organizations with sensitive research, public services, or communications infrastructure are particularly at risk.
Microsoft Details NeedyMantis Malware: A Stealthy Threat for Persistent Access
Microsoft has issued a warning regarding a newly discovered malware variant, dubbed NeedyMantis, which facilitates persistent access for attackers. This sophisticated threat leverages a multi-stage loading process, intricate obfuscation, and anti-analysis measures to maintain stealth and adaptability.
Table Of Content
Initial Infection and Evasion Tactics
The infection begins with a first-stage loader responsible for extracting a subsequent payload from a unique custom archive. This archive’s structure, including offsets, XOR keys, compression methods, and filenames, varies significantly between samples. This dynamic customization presents a considerable challenge for static detection tools and automated analysis systems, making it difficult to identify consistently.
In one sample analyzed by Microsoft, a malicious WinSparkle.dll file was found replacing the legitimate update component within the Poedit application. The loader itself utilizes several techniques to evade detection and analysis. It obfuscates API names and constants through stack strings, dynamically resolves Windows functions, and actively checks for debugger presence using ProcessDebugFlags and ThreadHideFromDebugger. Following these evasive maneuvers, it proceeds to extract a file named encryptbase64.ps1.
Despite its PowerShell file extension, encryptbase64.ps1 contains x64 shellcode. This shellcode is responsible for decoding and decompressing the primary component of NeedyMantis, which is stored in a highly minimized, custom executable format. This additional layer of disguise further complicates detection efforts.
Command and Control (C2) Communication
Once activated, the core NeedyMantis component takes control of command-and-control (C2) traffic and manages downloadable modules. Microsoft’s analysis revealed that the malware’s configuration points to the domain corp.tripswithengine[.]com over port 443, utilizing the URI /library/zip/ for communication.
The initial phase of communication involves an HTTPS request. During this exchange, compressed, Base64-encoded system details are embedded within a Set-Cookie header. These details encompass critical information such as the computer name, username, currently running processes, parent processes, installed files, and a comprehensive list of all active processes.
After this initial data exfiltration, the communication protocol is upgraded to WebSockets. This WebSocket connection then employs a custom binary protocol that incorporates XOR encoding, compression, and optional RC4 encryption, ensuring a high level of stealth and data integrity for C2 operations.
Modular Design and Threat Profile
NeedyMantis is designed to receive various commands from its operators, including instructions to load or unload modules, dispatch collected data, and disable active flags. Concurrently, it sends identification and keepalive messages back to the C2 server. While Microsoft has not yet confirmed the specific capabilities of the downloadable modules, the malware’s modular architecture is a significant concern. This design allows attackers to introduce new functionalities and adapt to evolving environments without needing to replace the core implant, making it an exceptionally effective tool for persistent and flexible access.
The targeted nature of NeedyMantis makes this campaign particularly relevant for security teams safeguarding sensitive research, critical public services, and vital communications infrastructure. Given that NeedyMantis is typically deployed only after an initial compromise, its discovery should immediately trigger a comprehensive incident investigation. This investigation must span potential credential theft, lateral movement within the network, the identification of persistence mechanisms, the analysis of staging servers, and a thorough review of attacker activities preceding the malware’s deployment.
What You Should Do
- Actively hunt for outbound network connections to the domain
corp.tripswithengine[.]com. - Monitor for unexpected DLL loads and suspicious decoding activities on your systems.
- Investigate any instances of Impacket execution, which could indicate lateral movement by attackers.
- Search for NeedyMantis files positioned alongside legitimate applications, a common tactic for sideloading.
- Enable cloud-delivered protection, block-at-first-sight features, and network protection in Microsoft Defender.
- Ensure Endpoint Detection and Response (EDR) is operating in block mode and leverage automatic attack disruption capabilities.
- Implement attack surface reduction rules to block untrusted executables and obfuscated scripts.
- Be aware of Microsoft Defender detections, including
TrojanDropper:Win64/NeedyMantis,Behavior:Win64/NeedyMantis, and alerts for suspicious sideloading or Impacket activity.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.