{"id":2069,"date":"2026-09-29T11:47:53","date_gmt":"2026-09-29T06:17:53","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=2069"},"modified":"2026-10-01T10:20:08","modified_gmt":"2026-10-01T04:50:08","slug":"needymantis-post-compromise-malware","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/needymantis-post-compromise-malware\/","title":{"rendered":"NeedyMantis malware: How a modular toolkit supports targeted intrusions"},"content":{"rendered":"<p>A familiar application name does not always mean familiar behavior. NeedyMantis malware uses legitimate software to launch malicious components after attackers have already entered an environment, with observed activity dating to at least October 2025.<\/p>\n<p>The post-compromise malware combines several loading stages with encrypted archives and modular functionality. This gives defenders a practical challenge: investigating what trusted-looking programs actually load and do.<\/p>\n    \t\t<div class=\"hts-messages hts-messages--info  hts-messages--withtitle  \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Who is Storm-3069?<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\tStorm-3069 is a tracking designation used by Microsoft Threat Intelligence for activity associated with the DAEMON Tools supply-chain compromise. It is one observed operator of NeedyMantis. The activity is assessed as originating from China, but it has not been attributed to a Chinese nation-state actor.<\/p>\n<p>The distinction matters: an assessed operating location does not establish government sponsorship. Additional NeedyMantis activity also leaves open the possibility of multiple operators. Defenders should therefore avoid treating the malware name as proof of a single group\u2019s involvement. Use the designation to organize relevant intelligence, while grounding response decisions in evidence from affected systems. Public reporting does not establish a complete history of this operator\u2019s targets or methods.    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h2>What happened?<\/h2>\n<h3>The confirmed picture<\/h3>\n<table>\n<thead>\n<tr>\n<th>Area<\/th>\n<th>Verified details<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Timeline<\/td>\n<td>Observed activity dates to at least October 2025.<\/td>\n<\/tr>\n<tr>\n<td>Affected sectors<\/td>\n<td>Telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors.<\/td>\n<\/tr>\n<tr>\n<td>Deployment<\/td>\n<td>DAEMON Tools was involved in the initial supply-chain compromise associated with Storm-3069. This does not establish direct supply-chain distribution of NeedyMantis itself. Attackers typically introduce the toolkit after obtaining access. A single initial-access method has not been established across intrusions.<\/td>\n<\/tr>\n<tr>\n<td>Software abuse<\/td>\n<td>Poedit, curl, Vim, and TightVNC were legitimate binaries leveraged post-compromise for local DLL sideloading. Other components used DLL names or paths resembling established vendors\u2019 software.<\/td>\n<\/tr>\n<tr>\n<td>Loading sequence<\/td>\n<td>A sideloaded DLL extracts another loader from a custom archive. Subsequent stages decode and decompress executable components.<\/td>\n<\/tr>\n<tr>\n<td>Operator communications<\/td>\n<td>WebSockets C2 supports communication with attacker infrastructure and commands for additional modules.<\/td>\n<\/tr>\n<tr>\n<td>Persistence<\/td>\n<td>An older analyzed archive contained a module using Windows services.<\/td>\n<\/tr>\n<tr>\n<td>Uncertainty<\/td>\n<td>Discovery through the DAEMON Tools investigation does not establish direct supply-chain distribution of NeedyMantis itself.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Why the loading chain matters<\/h3>\n<p>DLL sideloading involves a legitimate executable loading a malicious library. Investigators should therefore examine the relationship between the application, its loaded components, and their locations.<\/p>\n<p>In this case, encrypted and compressed archives, obfuscated strings, and anti-debugging techniques complicate analysis. However, these features do not make the malware undetectable. They make it important to examine execution behavior alongside file indicators.<\/p>\n<p>The main component also supports additional modules. Consequently, identifying the initial loader should begin a wider investigation into what else executed on the device.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/AI-patch-remediation.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>AI-Assisted Patch Remediation with Hexnode Genie<\/h4><p>Explore how AI-assisted patch remediation helps IT teams prioritize updates while retaining control.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/ai-patch-remediation-hexnode-genie\/\" aria-label=\"AI-Assisted Patch Remediation with Hexnode Genie\"><\/a><\/div><\/div><\/div><\/p>\n<h3>What the evidence does not establish<\/h3>\n<p>The available findings do not establish a campaign-wide phishing method, MFA bypass, ransomware deployment, or extortion demand. They also do not establish which sensitive records, if any, were stolen from each affected organization.<\/p>\n<p>Avoid turning potential access into a confirmed data-loss claim. Responders should determine affected accounts, accessible resources, and evidence of collection or transfer separately.<\/p>\n<h2>Why this matters<\/h2>\n<p>Security teams need to distinguish an approved application from an approved execution chain. A recognizable program can still warrant investigation when it loads unexpected files or contacts unfamiliar infrastructure.<\/p>\n<p>For targeted intrusions, focus on relationships: which account launched the process, where its components came from, and what happened next. File hashes help, but they should complement behavioral investigation rather than define its entire scope.<\/p>\n<p>Device, identity, and access controls also need to work together. Limit unnecessary software and privileges, review access from affected systems, and investigate suspicious sessions. MFA remains valuable, but teams should not treat a successful login as proof that the endpoint is safe.<\/p>\n<p>Prepare containment procedures before an alert arrives, including who can isolate devices and preserve evidence.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit-1.webp?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity-kit\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit-1.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit-1-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit-1-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit-1-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity-kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Feature Resource \n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            This resource kit will help your company adopt the right cybersecurity strategy to secure your business.\r\n\r\n\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            DOWNLOAD KIT\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h2>How Hexnode can help<\/h2>\n<h3>Hexnode UEM: Restrict unnecessary applications and identify policy gaps<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/\" rel=\"noopener\">Hexnode UEM<\/a> supports application blocklisting and allowlisting on supported Windows devices. Administrators can define executable rules using publisher or file-path conditions.<\/p>\n<p>Use these controls to restrict unapproved remote access utilities and reduce unnecessary applications. Test policies against business requirements before wider deployment.<\/p>\n<p>Application Compliance provides a separate assessment of installed software against configured lists. On supported Windows devices, it can identify application-related noncompliance, but it does not itself block execution or installation.<\/p>\n<p>These controls support software governance. They should not be described as automatic detection of malicious DLLs loaded by an approved executable.<\/p>\n<p>While allowlisting stops unauthorized binaries from executing, an allowlisted application can still run a sideloaded DLL in its execution path, highlighting the need to pair UEM application controls with XDR behavioral monitoring.<\/p>\n<h3>Hexnode XDR: Investigate endpoint activity and contain affected devices<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\" rel=\"noopener\">Hexnode XDR<\/a> provides endpoint investigation and response capabilities, including process analysis, process termination, kill process tree, file quarantine, and endpoint isolation. Isolation retains communication with the XDR console for continued response.<\/p>\n<p>For suspected compromise, analysts can use these capabilities to investigate activity and contain affected endpoints while determining the wider scope.<\/p>\n<p>This is a capability-based positioning, not a claim that Hexnode XDR has a verified NeedyMantis-specific detection. Teams should validate relevant detection coverage, agent deployment, and response permissions in their environment.<\/p>\n<h2>What security teams should do next<\/h2>\n<p>Treat a suspicious loader as a starting point for investigation. Establish when it appeared, which account introduced it, and which processes or connections followed.<\/p>\n<p>Then search for related activity across other endpoints. Review unexpected services, unfamiliar application directories, and remote administration activity that lacks a business explanation. Preserve relevant evidence before deleting files or rebuilding systems.<\/p>\n<p>Contain confirmed affected devices through your incident-response process. Investigate exposed accounts and sessions, and address the original entry point before returning systems to service. A removed file alone does not demonstrate that access has ended.<\/p>\n<p>Hexnode UEM can support tighter application policies, while Hexnode XDR provides investigation and containment controls. Use those capabilities within a response process that assigns clear owners and recovery criteria.<\/p>\n<p>Start by testing whether your team can trace an unusual application launch, isolate its endpoint, and verify recovery without losing the evidence needed to understand the intrusion.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Try\u202fHexnode\u202fFree for 14 Days\u202f\u202f\u202f<\/h5><p>Sign up for Hexnode to strengthen application controls and improve visibility across your endpoints.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign Up Today\u202f\u202f<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A familiar application name does not always mean familiar behavior. NeedyMantis malware uses legitimate software&#8230;<\/p>\n","protected":false},"author":8,"featured_media":2084,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15,16],"class_list":["post-2069","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware","category-windows","product_category-unified-endpoint-management","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>NeedyMantis malware: Inside targeted intrusions<\/title>\n<meta name=\"description\" content=\"Microsoft detailed NeedyMantis, a modular post-compromise malware family using DLL sideloading, encrypted archives, and WebSockets C2.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/needymantis-post-compromise-malware\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NeedyMantis malware: Inside targeted intrusions\" \/>\n<meta property=\"og:description\" content=\"Microsoft detailed NeedyMantis, a modular post-compromise malware family using DLL sideloading, encrypted archives, and WebSockets C2.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/needymantis-post-compromise-malware\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-29T06:17:53+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-10-01T04:50:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/NeedyMantis-malware.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Alanna River\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alanna River\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/needymantis-post-compromise-malware\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/needymantis-post-compromise-malware\\\/\"},\"author\":{\"name\":\"Alanna River\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\"},\"headline\":\"NeedyMantis malware: How a modular toolkit supports targeted intrusions\",\"datePublished\":\"2026-09-29T06:17:53+00:00\",\"dateModified\":\"2026-10-01T04:50:08+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/needymantis-post-compromise-malware\\\/\"},\"wordCount\":1015,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/needymantis-post-compromise-malware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/NeedyMantis-malware.png?format=webp\",\"articleSection\":[\"Malware\",\"Windows\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/needymantis-post-compromise-malware\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/needymantis-post-compromise-malware\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/needymantis-post-compromise-malware\\\/\",\"name\":\"NeedyMantis malware: Inside targeted intrusions\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/needymantis-post-compromise-malware\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/needymantis-post-compromise-malware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/NeedyMantis-malware.png?format=webp\",\"datePublished\":\"2026-09-29T06:17:53+00:00\",\"dateModified\":\"2026-10-01T04:50:08+00:00\",\"description\":\"Microsoft detailed NeedyMantis, a modular post-compromise malware family using DLL sideloading, encrypted archives, and WebSockets C2.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/needymantis-post-compromise-malware\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/needymantis-post-compromise-malware\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/needymantis-post-compromise-malware\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/NeedyMantis-malware.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/NeedyMantis-malware.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"NeedyMantis malware\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/needymantis-post-compromise-malware\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"NeedyMantis malware: How a modular toolkit supports targeted intrusions\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\",\"name\":\"Alanna River\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"caption\":\"Alanna River\"},\"description\":\"I\u2019m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/alanna-river\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NeedyMantis malware: Inside targeted intrusions","description":"Microsoft detailed NeedyMantis, a modular post-compromise malware family using DLL sideloading, encrypted archives, and WebSockets C2.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/needymantis-post-compromise-malware\/","og_locale":"en_US","og_type":"article","og_title":"NeedyMantis malware: Inside targeted intrusions","og_description":"Microsoft detailed NeedyMantis, a modular post-compromise malware family using DLL sideloading, encrypted archives, and WebSockets C2.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/needymantis-post-compromise-malware\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-29T06:17:53+00:00","article_modified_time":"2026-10-01T04:50:08+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/NeedyMantis-malware.png?format=webp","type":"image\/png"}],"author":"Alanna River","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Alanna River","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/needymantis-post-compromise-malware\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/needymantis-post-compromise-malware\/"},"author":{"name":"Alanna River","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64"},"headline":"NeedyMantis malware: How a modular toolkit supports targeted intrusions","datePublished":"2026-09-29T06:17:53+00:00","dateModified":"2026-10-01T04:50:08+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/needymantis-post-compromise-malware\/"},"wordCount":1015,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/needymantis-post-compromise-malware\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/NeedyMantis-malware.png?format=webp","articleSection":["Malware","Windows"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/needymantis-post-compromise-malware\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/needymantis-post-compromise-malware\/","url":"https:\/\/www.hexnode.com\/threat-watch\/needymantis-post-compromise-malware\/","name":"NeedyMantis malware: Inside targeted intrusions","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/needymantis-post-compromise-malware\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/needymantis-post-compromise-malware\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/NeedyMantis-malware.png?format=webp","datePublished":"2026-09-29T06:17:53+00:00","dateModified":"2026-10-01T04:50:08+00:00","description":"Microsoft detailed NeedyMantis, a modular post-compromise malware family using DLL sideloading, encrypted archives, and WebSockets C2.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/needymantis-post-compromise-malware\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/needymantis-post-compromise-malware\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/needymantis-post-compromise-malware\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/NeedyMantis-malware.png?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/NeedyMantis-malware.png?format=webp","width":1340,"height":700,"caption":"NeedyMantis malware"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/needymantis-post-compromise-malware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"NeedyMantis malware: How a modular toolkit supports targeted intrusions"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64","name":"Alanna River","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","caption":"Alanna River"},"description":"I\u2019m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/alanna-river\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2069","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=2069"}],"version-history":[{"count":3,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2069\/revisions"}],"predecessor-version":[{"id":2077,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2069\/revisions\/2077"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/2084"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=2069"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=2069"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}