Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Microsoft Threat Intelligence has identified NeedyMantis, a modular post-compromise malware family observed in a limited number of targeted operations. The malware is typically deployed after a threat actor has established access, and is used to maintain long-term access and support follow-on operations.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The first-stage loader extracts a second-stage payload from a custom archive whose offsets, XOR keys, compression, and filenames change between samples. The loader concealed API names and constants using obfuscated stack strings.
An initial HTTPS request places compressed, Base64-encoded system details inside a Set-Cookie header, including the computer name, username, running process, parent process, installed files, and process list.
An initial HTTPS request places compressed, Base64-encoded system details inside a Set-Cookie header, including the computer name, username, running process, parent process, installed files, and process list.
An initial HTTPS request places compressed, Base64-encoded system details inside a Set-Cookie header, including the computer name, username, running process, parent process, installed files, and process list.
An initial HTTPS request places compressed, Base64-encoded system details inside a Set-Cookie header, including the computer name, username, running process, parent process, installed files, and process list.
Communication then upgrades to WebSockets and uses a custom binary protocol with XOR encoding, compression, and optional RC4 encryption.
Its configuration pointed to corp.tripswithengine[.]com over port 443 and the URI /library/zip/. Communication then upgrades to WebSockets.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular post-compromise implant intended for covert, persistent espionage-oriented access. Its core component manages HTTPS/WebSocket command-and-control and can load or unload downloadable modules. It collects host and process details, uses encoded/compressed communications with optional RC4 encryption, and is deployed through DLL sideloading after initial access.
A post-compromise malware family used in targeted operations. The supplied content provides no further technical capabilities, targeting, attribution, or delivery details.
NeedyMantis is a selectively deployed modular post-compromise framework used for persistent access and follow-on intrusion activity. It uses DLL sideloading with legitimate software, custom encrypted/compressed archives, staged loaders, shellcode, anti-debugging and string obfuscation. Its main component communicates with C2 over HTTPS upgraded to WebSockets, collects basic host information, and can load, unload, and dispatch data to additional modules whose capabilities are not yet confirmed.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.