HIGHmalware·

NeedyMantis: Modular Post-Compromise Malware Framework

NeedyMantis is a modular post-compromise malware framework identified by Microsoft Threat Intelligence. It employs custom loaders, encrypted archives, and extensible components to maintain long-term access and facilitate follow-on operations in targeted intrusions.

This report was researched and drafted by an AI agent and reviewed by a human analyst prior to publication. View the agent workflow →

Overview

NeedyMantis is a modular post-compromise malware framework used in targeted intrusions. It leverages custom loaders, encrypted archives, and extensible components to establish and maintain long-term access, enabling subsequent malicious operations. Microsoft Threat Intelligence identified this framework in use against specific targets.

Technical Analysis

  • NeedyMantis operates as a modular framework, allowing threat actors to deploy various components as needed.
  • It utilizes custom loaders, suggesting a tailored approach to initial execution and evasion.
  • The framework employs encrypted archives, likely for storing its components, exfiltrating data, or obscuring malicious payloads.
  • Designed for extensibility, indicating a capability for threat actors to adapt and expand its functionalities post-compromise.
  • The primary objective is to maintain long-term access within compromised environments and support follow-on activities.

Detection

  • Monitor for suspicious process creation chains, particularly legitimate processes (e.g., svchost.exe, explorer.exe) spawning unusual executables in non-standard paths.
  • Look for the creation or modification of encrypted archive files (e.g., .zip, .rar, .7z) in unexpected directories, especially by processes not typically associated with archiving.
  • Analyze network traffic for unusual outbound connections to unknown or suspicious IP addresses and domains, indicative of command-and-control (C2) communication.
  • Hunt for registry modifications or scheduled tasks establishing persistence, especially those pointing to newly created or modified executables.
  • Monitor for unusual file system activity, such as the creation of hidden files or directories, or modifications to system binaries.

Sigma Detection Rules

⚠️ AI-generated detection rules. These are experimental starting points. Review field names, EventIDs, and logic against your environment’s schema before deploying. Tune to reduce false positives.

Suspicious Process Spawning from Legitimate Parent

title: Suspicious Process Spawning from Legitimate Parent
id: 9c1d2e3f-4a5b-6c7d-8e9f-0123456789ab
status: experimental
description: Detects suspicious process creation where a common legitimate Windows process spawns an unusual executable in a non-standard path, indicative of a custom loader or malware execution.
logsource:
  product: windows
  service: sysmon
detection:
  selection:
    ParentImage|endswith:
      - '\\svchost.exe'
      - '\\explorer.exe'
      - '\\lsass.exe'
    Image|contains:
      - 'C:\Users\Public\'
      - 'C:\ProgramData\'
      - 'C:\Windows\Temp\'
      - 'C:\PerfLogs\'
    Image|endswith:
      - '.exe'
      - '.dll'
    CommandLine|contains:
      - ' -load'
      - ' -exec'
  condition: selection
level: high

Creation of Encrypted Archive in Suspicious Location

title: Creation of Encrypted Archive in Suspicious Location
id: a1b2c3d4-e5f6-7a8b-9c0d-1234567890ef
status: experimental
description: Detects the creation of common encrypted archive file types in user profile or system temporary directories, which could indicate data staging for exfiltration or malware component storage.
logsource:
  product: windows
  service: sysmon
detection:
  selection:
    EventID: 11 # FileCreate
    TargetFilename|endswith:
      - '.zip'
      - '.rar'
      - '.7z'
      - '.gz'
      - '.tar.gz'
    TargetFilename|contains:
      - 'C:\Users\'
      - 'C:\Windows\Temp\'
      - 'C:\ProgramData\'
  condition: selection
level: medium

Registry Persistence via Run Key for Suspicious Path

title: Registry Persistence via Run Key for Suspicious Path
id: b2c3d4e5-f6a7-8b9c-0d1e-2345678901fg
status: experimental
description: Identifies modifications to common Windows Run registry keys that point to executables in non-standard or temporary directories, a common persistence mechanism for malware like NeedyMantis.
logsource:
  product: windows
  service: sysmon
detection:
  selection:
    EventID: 13 # RegistryEvent (Value Set)
    TargetObject|contains:
      - 'Software\Microsoft\Windows\CurrentVersion\Run\'
      - 'Software\Microsoft\Windows\CurrentVersion\RunOnce\'
    Details|contains:
      - 'C:\Users\Public\'
      - 'C:\ProgramData\'
      - 'C:\Windows\Temp\'
      - 'C:\PerfLogs\'
      - '.exe'
      - '.dll'
  condition: selection
level: high

Mitigations

  1. Implement robust Endpoint Detection and Response (EDR) solutions to detect and respond to post-compromise activities, including suspicious process execution and file modifications.
  2. Enforce application whitelisting or strong application control policies to prevent the execution of unauthorized or unknown executables and scripts, including custom loaders.
  3. Regularly patch and update all operating systems, applications, and network devices to remediate known vulnerabilities that could be exploited for initial access.
  4. Implement network segmentation and egress filtering to limit lateral movement and restrict outbound connections to only necessary and approved destinations.
  5. Conduct regular security audits and penetration testing to identify and address weaknesses in your environment before they can be exploited.

References

  • https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/

Indicators of Compromise

No public IOCs available at time of writing.

MITRE ATT&CK

🤖 AI Attribution
Generated by gemini-2.5-flash ·
1,611 input / 1,597 output tokens ·
Reviewed and approved by a human analyst before publication
#malware#high#malware#persistence#post-compromise#targeted-attack#windows