NeedyMantis: Unpacking a post-compromise malware family used in targeted operations (opens in a new tab)
Why readFirst public analysis of NeedyMantis, a modular post-compromise implant tied to the DAEMON Tools supply chain compromise, with IOCs and hunting queries for telecom, university and government-contractor networks.
Microsoft Threat Intelligence documents NeedyMantis, a modular malware family deployed after initial access to maintain long-term persistence and support follow-on operations, with activity traced back to at least October 2025. It was discovered by pivoting from indicators associated with the DAEMON Tools supply chain compromise that Kaspersky previously reported. Targeting spans telecommunications firms, universities, medical nonprofits, intergovernmental organisations and government contractors; the post ships architecture and capability detail, hunting queries and indicators of compromise.
Indicators4
- Hashes
e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077efc82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77- Domains
corp[.]tripswithengine[.]com