
NeedyMantis DLL sideloading observed in Poedit and curl bundles since October 2025 across five sectors
NeedyMantis provides a documented case of sustained post-compromise access through DLL sideloading rather than novel supply-chain distribution. Multiple Chinese-nexus actors appear to share the tool without confirmed coordination. Its limited deployment footprint and WebSocket C2 architecture highlight detection gaps that persist after initial breach remediation.
The evidence trail shows three-stage loaders that decrypt an archive after DLL sideloading, then establish HTTPS-to-WebSocket channels for module loading. Older October 2025 samples included a Windows service persistence module; the analyzed variant omits public detail on current persistence mechanisms. Impacket lateral movement indicates operators already held network access before deployment, separating initial access from the observed persistence layer.
Microsoft attributes Storm-3069 activity to China-origin operators based on target selection and limited victim count, yet stops short of naming a known group. Mandiant separately labeled UNC6863 a suspected China-nexus actor behind the April-May 2026 DAEMON Tools supply-chain compromise; Kaspersky noted Chinese-language strings without attribution. No technical artifacts have been published that confirm or refute overlap between Storm-3069 and UNC6863.
Long-term network persistence receives less coverage than initial access vectors, yet NeedyMantis demonstrates how post-breach tooling can remain undetected for months in high-value environments. The malware's reuse of signed binaries from Poedit, curl, Vim, and TightVNC reduces behavioral detection surface while enabling selective module deployment.
Defenders should prioritize the published file hashes and Impacket execution paths; future module recovery will clarify whether exfiltration or credential-harvesting components are active.
Microsoft: At least two additional NeedyMantis C2 domains will appear in public IOC lists within 120 days
Sources (3)
- [1]Microsoft Threat Intelligence(https://www.microsoft.com/security/blog)
- [2]Mandiant UNC6863 Analysis(https://www.mandiant.com/resources)
- [3]Kaspersky DAEMON Tools Supply Chain Report(https://www.kaspersky.com/blog)