Feed aggregator
Quine's Paradox
Article URL: https://en.wikipedia.org/wiki/Quine%27s_paradox
Comments URL: https://news.ycombinator.com/item?id=49879385
Points: 1
# Comments: 0
One Quarter of Global Data Centers Are Located in Water-Stressed Areas
Skill Acquisition
Article URL: https://elijahpotter.dev/articles/skill-acquisition
Comments URL: https://news.ycombinator.com/item?id=49879366
Points: 2
# Comments: 1
The Perl Toolchain Summit 2027
Article URL: https://www.perl.com/article/announcing-the-perl-toolchain-summit-2027/
Comments URL: https://news.ycombinator.com/item?id=49879362
Points: 1
# Comments: 0
Dear User of the Universe
Article URL: https://blog.sebastiansastre.co/posts/dear-user-of-the-universe/
Comments URL: https://news.ycombinator.com/item?id=49879348
Points: 2
# Comments: 0
Getting out of the way: my robotics crash course
Article URL: https://thisismypersonalblog.com/posts/2026-09-25-getting-out-of-the-way/
Comments URL: https://news.ycombinator.com/item?id=49879346
Points: 1
# Comments: 0
What makes Lisp difficult to read?
Article URL: https://paultm.nl/paren-thesis
Comments URL: https://news.ycombinator.com/item?id=49879343
Points: 1
# Comments: 0
Pragmatic Anthropomorphism, Or: How to Talk to an Autocompleting Cricket
Article URL: https://blog.lmorchard.com/2026/09/27/pragmatic-anthropomorphism/
Comments URL: https://news.ycombinator.com/item?id=49879335
Points: 1
# Comments: 0
Citrix NetScaler PreAuth Command Injection CVE-2026-88771
Earth's mysterious 'hum' points to the sound of waves crashing across the world
Article URL: https://www.abc.net.au/news/2026-08-28/could-ocean-waves-be-making-earth-hum/107080976
Comments URL: https://news.ycombinator.com/item?id=49879306
Points: 1
# Comments: 0
The Front Wire, a breaking-news wire built on primary sources
Article URL: https://frontwire.thecompound.tech
Comments URL: https://news.ycombinator.com/item?id=49879304
Points: 1
# Comments: 0
The Code Nobody Reads
Article URL: https://addyo.substack.com/p/the-code-nobody-reads
Comments URL: https://news.ycombinator.com/item?id=49879294
Points: 1
# Comments: 0
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.
According to three sources familiar with the matter, the Dutch man arrested by authorities this month is Pepijn van der Stap, a convicted cybercriminal from Almere and Leylstad in the Netherlands. Van der Stap was previously convicted in 2023 in connection with a string of data thefts and extortions that prosecutors said earned between €1.5 million and €2.7 million.
At his trial in late 2023, van der Stap admitted that he lived a Dr. Jekyll and Mr. Hyde existence, secretly using the hacker handle “Umbreon” to extort victims and post their data on English language hacking communities like the now-defunct RaidForums and Breached. By day, however, van der Stap was working as a software engineer at the Amsterdam-based cybersecurity startup Hadrian, while volunteering at the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit security research group.
Pepijn van der Stap’s alter ego “Umbreon” selling a database on RaidForums, offering information on 2.3 million people from The Netherlands in September 2021. This user’s avatar is a depiction of the Pokemon character Umbreon. Image: KELA.
Van der Stap confessed to his data theft and extortion activity, and was sentenced to four years in prison (one of which was suspended). During his trial, van der Stap opted to remain in custody for a time rather than at home, saying he could not find better treatment on the outside for his ongoing psychological issues, which he claimed included PTSD related to childhood trauma. He was released from prison in December 2025.
In an interview with KrebsOnSecurity on September 9, 2026, Van der Stap cast himself as a reformed hacker who was trying to turn his life around and make a positive contribution to society. Van der Stap is currently employed as offensive security lead at the Dutch company Neo Security, which did not respond to requests for comment.
Van der Stap said he was still dealing with civil lawsuits and restitution related to his previous cybercrime victims, and that he was trying his best to make amends. But not long after that interview, the Dutch hacker abruptly stopped replying to messages. Efforts by others close to him also repeatedly failed to elicit a response for the past two weeks.
The LinkedIn profile for Pepijn van der Stap.
According to two sources with knowledge of the matter, Van der Stap was arrested by Dutch authorities on or around September 16, and has been held in custody for questioning since. One source said a colleague of theirs personally witnessed Dutch authorities carting items out of Van der Stap’s residence.
Authorities in the Netherlands have been asking the public for help in identifying the voice in a recorded telephone call from February 2026 in which a native Dutch-speaking ShinyHunters member social engineered their way into Odido, the nation’s largest mobile telecommunications provider. In that intrusion, ShinyHunters tricked an Odido employee into logging in at a spoofed website, and then used that access to steal data on more than 6.2 million Dutch people.
Responding to Dutch news media, ShinyHunters confirmed that the suspect in the audio clip is indeed a member of the hacker collective.
“Our team member has our full support – emotionally, mentally, and financially,” the hackers said. “Everything has been arranged, including a criminal defense lawyer. We do not look down on our staff and members; we take excellent care of them,” reads a statement ShinyHunters shared with NL Times. It remains unclear if the Dutch police have matched the Odido caller to a confirmed real-life identity. The Dutch police unit handling the Odido incident did not respond to requests for comment.
The group also lashed out at the authorities in the Netherlands. “The Dutch police will need all the luck in the world – and everyone’s prayers – if they want to catch him before we carry out another large-scale data theft in the Netherlands,” the ShinyHunters statement said. “Frankly, the Dutch police are a big joke; they are incapable of doing anything. Incompetent. Irrelevant. Unimportant. Useless.”
FBI, CL0P HACKSJust days after sources say Van der Stap was detained by Dutch authorities, ShinyHunters claimed credit for an unusually brazen breach at the FBI’s job application site apply.fbijobs.gov. According to reporting from 404 Media, the data stolen from the FBI site includes Social Security numbers and personal information on more than 5,000 officials.
404 Media and Reuters reported the FBI data included each person’s job title or team, such as special agent, threat intake examiner, major cybercrimes unit, and those investigating cyber threats from foreign state-backed actors. Reuters examined documents shared by ShinyHunters and found they included sensitive psychiatric and medical files of FBI staff. The FBI issued a brief statement confirming the hack.
ShinyHunters said it gained access to the FBI site and other victims by exploiting a recently patched vulnerability (CVE-2026-35273) in PeopleSoft, a software-as-a-service platform from the software giant Oracle that is broadly used by companies to manage hiring and human resources, benefits and payroll. Oracle quickly issued a fix for the Peoplesoft vulnerability that ShinyHunters reportedly began exploiting as a zero-day in June, and at the time Mandiant released web application firewall rules intended for organizations who couldn’t apply the security update quickly enough.
But on Friday, BleepingComputer reported that ShinyHunters used a URL-encoding trick to bypass Mandiant’s suggested web application firewall rules designed to mitigate the threat from the PeopleSoft flaw. In a report released Sept. 25, security experts at Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.
Van der Stap’s former hacker alias Umbreon was hidden in plain sight throughout the imagery ShinyHunters used to spread news about the FBI hack: The defacement image that ShinyHunters left behind on the hacked FBI jobs site included an ASCII art design featuring the Pokemon character Umbreon. The message at the top read, “This site has been seized by ShinyHunters. rooting your systems since ’19 ;)” The image appears identical to a defacement message ShinyHunters used in their 2020 hack of the English-language cybercrime community Hackforums.
The defacement message left by ShinyHunters on the FBI jobs site included an ASCII art rendition of the Pokemon character Umbreon. Image: Bleeping Computer.
Multiple sources close to the ShinyHunters investigation said the group’s recent risky attacks against the FBI and one of Russia’s most venerated ransomware groups amounted to a major pivot away from the more measured tenor of the hacking gang’s operations. Those sources said the sudden shift came about after ShinyHunters was taken over by a teenage cybercriminal from Amman, Jordan who goes by the nickname Rey and operates as part of a cybercrime group called ScatteredLapsussHunters (SLSH), which experts say is an amalgamation of three hacking groups — Scattered Spider, LAPSUS$ and ShinyHunters.
Those sources said Rey had an ongoing beef with the Dutch hacker over control of the ShinyHunters brand and data, and that the inclusion of the oversized Umbreon Pokemon image in the FBI jobs site defacement was likely an attempt by Rey to pin the hack on the Dutchman.
Rey was first publicly identified by the cybersecurity firm KELA in March 2025. In advance of our November 2025 profile of Rey, KrebsOnSecurity messaged Rey’s father and asked for permission to interview his teenage son. Rey’s dad merely forwarded the message to his son, who admitted to participating in ransomware attacks and said he was trying to extricate himself from the SLSH hacker group.
BLAMING UMBREONImmediately after news of the FBI jobs site hack was picked up in the media, Rey’s main account on Twitter/X (Ryan Moran/@rmoskovy) was taunting the Cl0p ransomware group and the FBI, crudely depicting them as the twin towers in New York being struck by planes labeled “cl0p drama” and “fbi breach claim.” In the foreground of the city is the giant Pokemon figure of Umbreon.
A taunting meme uploaded to Twitter/X by Rey’s now-defunct account on Sept. 22. A giant float-sized version of the Pokemon character Umbreon can be seen in the bottom left.
On Sept. 24, KrebsOnSecurity again contacted Rey’s dad, asking to interview him and his son for a story on Rey’s apparent ascendency as the head of ShinyHunters. Just hours after that request, Rey deleted his longtime Twitter/X account. Meanwhile, Rey’s dad, who works for the Royal Jordanian Airlines, has failed to respond to a half-dozen emailed requests for comment about his son’s alleged activities.
Where does the bad blood between SLSH and ShinyHunters come from? According to a story in Wired this month, ShinyHunters and SLSH members briefly partnered earlier this year to help better monetize important stolen credentials collected by TeamPCP, an upstart group that was having great success compromising global code supply chains with malicious software but hadn’t been able to profit much from their stolen data (two alleged leaders of TeamPCP were arrested last month in Australia, and in an interview the TeamPCP leader claimed they made just $20,000).
The Wired story noted how Mandiant had infiltrated TeamPCP and was secretly responsible for having the crime group’s stolen credentials burned so quickly: A Mandiant researcher was secretly feeding those credentials to the major cloud providers like Amazon and Microsoft, who quickly invalidated the stolen keys. Meanwhile, the formerly cooperating hacker groups began to blame one another for causing the credentials to become worthless.
Wired’s Andy Greenberg reported that a few weeks after partnering with TeamPCP, “ShinyHunters went rogue, carrying out its own extortions with TeamPCP’s credentials but without giving the supply-chain hackers their cut.”
Mandiant researcher Austin Larsen told KrebsOnSecurity earlier this month that ShinyHunters has been enjoying a successful extortion spree so far this year, and is on track to pull in nearly $100 million in extortion payments from cybercrime victims in 2026.
Van der Stap claims he was never motivated by money and that his earlier hacker activity was driven by a desire to have the world’s most complete collection of stolen databases. Speaking with reporters from Bloomberg in 2024, Van der Stap said that singular focus in turn fueled his desire to carry out cyberattacks.
“The hacking was very easy for me, and it wasn’t a compulsion,” he told Bloomberg. “My habit was collecting. Collecting data, organizing data, downloading data, creating folders.”
DIVD, the nonprofit security research group where Van der Stap previously served as a volunteer, disclosed on LinkedIn last week that the organization was dealing with an internal cybersecurity incident that appears to have involved the malicious use of artificial intelligence. DIVD has released few details about that incident, but a spokesperson for the nonprofit told KrebsOnSecurity it does not appear related to ShinyHunters, nor are there any signs the matter involves the work of a previous volunteer.
UK government tells staff to stop thanking AI chatbots
Using C++17 Std:Optional
Article URL: https://www.cppstories.com/2018/05/using-optional/
Comments URL: https://news.ycombinator.com/item?id=49879265
Points: 1
# Comments: 0
ProjecturEd: One data structure, many editable views, with an AI assistant
Article URL: https://projectured.org
Comments URL: https://news.ycombinator.com/item?id=49879262
Points: 1
# Comments: 1
Space Lasers Are About to Get Their First Real Test Generating Energy
Article URL: https://www.wired.com/story/space-lasers-are-about-to-get-their-first-real-test-generating-energy/
Comments URL: https://news.ycombinator.com/item?id=49879261
Points: 1
# Comments: 0
Strata: Qwen3.8-Flash-Next (125B Moe) on a 8GB+ Nvidia GPU
Article URL: https://github.com/Niko1221/Strata
Comments URL: https://news.ycombinator.com/item?id=49879253
Points: 1
# Comments: 0
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
- Observed operators and targeting
- Malware packaging and distribution
- NeedyMantis architecture and capabilities
- Mitigation and protection guidance
- Hunting queries
- Indicators of compromise
Microsoft Threat Intelligence has identified NeedyMantis, a modular post-compromise malware family observed in a limited number of targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Based on observed activity, NeedyMantis is typically deployed after a threat actor has already established access to a target environment, indicating that the malware is used to maintain long-term access and support follow-on operations.
NeedyMantis activity dates back to at least October 2025. We discovered the malware family while analyzing and pivoting from research and indicators of compromise associated with the DAEMON Tools supply chain compromise, which Kaspersky previously reported on as part of its investigation into the campaign. Observed activity involving NeedyMantis has thus far aligned with activity that Microsoft associates with threat actors operating from China, although Microsoft has not determined whether all observed activity is attributable to the same operator.
While NeedyMantis employs techniques commonly used by modern malware, its architecture combines multiple loaders, custom encrypted file archives, a custom executable file format, and modular components that enable operators to evade analysis and extend functionality through additional modules. These characteristics, combined with its use in targeted intrusions, make NeedyMantis a useful case study for understanding how threat actors establish and maintain long-term access within victim environments.
In this blog, we analyze the NeedyMantis malware framework. We examine its packaging and deployment, custom archive format, loader architecture, command-and-control (C2) communications, and modular design. We also provide indicators of compromise (IOCs), Microsoft Defender detections, and mitigation guidance to help organizations defend against this threat and related activity.
Observed operators and targetingAt the time of writing, Microsoft has observed at least one threat actor using NeedyMantis malware: Storm-3069. Storm-3069 is Microsoft Threat Intelligence’s designator for activity associated with the DAEMON Tools supply chain compromise. While Microsoft assesses the activity originates from China, it has not attributed Storm-3069 to a Chinese nation-state actor. Microsoft identified NeedyMantis through follow-on analysis of indicators associated with Kaspersky’s investigation of the DAEMON Tools compromise.
Microsoft has observed additional NeedyMantis activity beyond Storm-3069’s activity in the DAEMON Tools campaign, indicating that the malware might be used by more than one operator. Observed activity involving NeedyMantis has thus far aligned with activity Microsoft associates with threat actors operating from China, such as targeting that aligns with Chinese interests and the use of selective deployment.
NeedyMantis has been observed in intrusions affecting telecommunications organizations, universities, intergovernmental organizations, medical nonprofits, and government contractors. Combined with the malware’s limited observed deployment and alignment with activity Microsoft associates with China-based threat actors, this victimology suggests NeedyMantis is deployed selectively rather than broadly. However, Microsoft has not determined whether all observed activity is attributable to the same threat actor or whether multiple actors have access to the malware.
Malware packaging and distributionAs previously mentioned, observed activity suggests that the malware is typically deployed after a threat actor has established access to a target environment. As a result, the methods used to gain access before NeedyMantis is deployed may vary across intrusions.
NeedyMantis is composed of multiple components written in C++ and x64 shellcode. The malware starts with a first-stage loader and a file archive. The loader and archive have been found packaged alongside legitimate software, with the first-stage loader–masquerading as a required DLL—being loaded through DLL sideloading.
Some of the open-source, software abused by the malware include: Poedit (translation), curl (data transfer), Vim (text editor), and TightVNC (remote access). Microsoft has also observed NeedyMantis masquerading as Microsoft Office, Broadcom, Intel, and NVIDIA DLL components. The following is a list of some of the DLL path names used by the malware:
- %ProgramFiles%\Poedit\WinSparkle.dll
- %ProgramData%\USOShared\libcurl.dll
- %ProgramData%\VIM\vim64.dll
- %ProgramData%\TightVNC\VIM\vim64.dll
- %ProgramData%\office\dbghelp.dll
- %ProgramData%\broadcom\dbghelp.dll
- %ProgramData%\Intel\jli.dll
- %ProgramFiles%\modifiable\nvml.dll
- %ProgramData%\ics\nvml.dll
The malware’s file archive is named the same as the loader DLL without the extension, for example WinSparkle or libcurl.
In one observed incident, an operator used the Impacket toolkit during hands-on-keyboard activity to copy the legitimate software, malicious DLL, and file archive from a network share and execute it on a targeted device. This activity occurred after the actor had already obtained access to the environment and illustrates one method by which NeedyMantis can be introduced during an intrusion post-compromise.
NeedyMantis is observed during the post-compromise stage of an intrusion after an actor has established access to the target environment. While one known user of the malware, Storm-3069, has been associated with supply chain compromises, Microsoft has not observed NeedyMantis itself being distributed through a supply chain compromise. However, supply chain activity remains one possible means by which an actor could gain the access necessary to deploy the malware.
NeedyMantis architecture and capabilities First-stage loaderNeedyMantis’ first-stage loader is DLL sideloaded and launched when the legitimate software it is packaged with is run. Its only task is to extract the second-stage loader from its file archive and continue execution there.
In the analyzed sample, the loader DLL was named WinSparkle.dll (SHA-256: e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e) and its file archive was named WinSparkle (SHA-256: 9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef). NeedyMantis spoofed and replaced the WinSparkle software update component of the Poedit translation software.
The loader employs common anti-analysis techniques to hinder analysis, like obfuscating most of its important strings.
Figure 1. Example obfuscated strings being deobfuscatedThis technique is known as obfuscated stack strings because each piece of the string is built up one at a time on the function’s stack. Once built up, it is deobfuscated using various mathematical operations. Most of the obfuscated strings in this loader are Windows DLL and API names. These deobfuscated strings are used to resolve Windows APIs dynamically at runtime.
In addition to obfuscated strings, a lot of the code’s constant values are stored obfuscated as well.
Figure 2. Example obfuscated constant value “1032” being deobfuscatedFinally, the loader has two anti-debugger methods: one based on ProcessDebugFlags and the other using ThreadHideFromDebugger.
As noted above, the loader’s main objective is to extract the next stage from its file archive and launch it. In the analyzed sample, the next stage was named encryptbase64.ps1.
Custom file archivesNeedyMantis’ file archives are in an encrypted and compressed custom file format. To get access to the files, the outer layer of the archive is XOR-decoded and RtlDecompressBuffer decompressed. Once decompressed, there are individual file entries. In each file entry, the file’s name is XOR-decoded and its contents are RtlDecompressBuffer decompressed.
The file format’s offsets, XOR keys, and values change from sample to sample.
Figure 3. Example output of an archive unpacking tool displaying metadata of the WinSparkle file archiveThis archive contains the following 11 files:
- 7-zip.chm – Legitimate component of 7-Zip
- 7-zip.dll – Legitimate component of 7-Zip
- 7-zip32.dll – Legitimate component of 7-Zip
- 7z.exe – Legitimate component of 7-Zip
- Disk2vhd.dll – Legitimate Sysinternals component Disk2vhd
- main.dll – Legitimate Sysinternals component Ctrl2Cap
- kernel32.dll – Legitimate kernel32.dll
- encryptbase64.ps1 – Second-stage loader
- dnsapi.dll – Not a dnsapi.dll, but contains the malware’s configuration
- ws2_32.dll – Not a ws2_32.dll, but contains a WebSockets based communications DLL
- msvcrt140.dll – Not a msvcrt140.dll, but contains shellcode to load module DLLs and resolve exports
While this archive contains several legitimate software components, the malware’s functionality is implemented by the remaining files, discussed below.
Other analyzed NeedyMantis file archives have contained different file names and components. An older version of the malware, for example, used a libcurl (SHA-256: c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77) file archive, and it contained only four files:
- 300.c – Malware’s configuration
- 300.s – WebSockets-based communications DLL
- is – Persistence module using Windows Services
- m.l – Main component
In the analyzed sample, encryptbase64.ps1 was the second-stage loader. Despite its .ps1 PowerShell extension, the file contains x64 shellcode. Its purpose is to decode and decompress an embedded binary which is NeedyMantis’ main component.
This loader also has some anti-analysis functionality that differs from stage one. For string decoding, it locates two encoded blocks of data and XOR keys at calculated offsets and then decodes them. The first block, most relevantly, contains a few Windows DLL and API names that are resolved dynamically. The second block, shown below, contains a list of Windows DLL names and Windows API hash values:
Figure 4. Decoded Windows API hash valuesThe component uses a rotate right (ROR) based algorithm with a configurable rotation value (the analyzed sample used value 11) to resolve these Windows API hashes. Figure 5 shows a snippet of Python code reproducing the algorithm:
Figure 5. Python snippet of Windows API hashing algorithmThis second-stage loader’s objective is to extract embedded data, XOR-decode it, and then RtlDecompressBuffer decompress it. The location of the encoded data and XOR key are at calculated offsets, which change from sample to sample.
Once decoded the resulting data is a DLL that has been formatted using a custom executable file format. It is a minimized version of a PE file.
Figure 6. Example output of custom executable file format to PE file conversion tool Main componentNeedyMantis’ main component orchestrates C2 communications and handles additional downloaded modules.
It creates a mutex named <username>-<process name>, such as Contoso-Poedit.exe. Like in the first-stage loader, most of the main component’s strings and constant values are stored as obfuscated stack strings.
ConfigurationThe malware’s configuration was stored in a dnsapi.dll file from the custom file archive. This file name spoofs a Windows networking library. In the sample analyzed, the file contains a 3448-byte binary structure. The structure includes the following fields:
- 0x00: Unknown (config contained “300”, but components also reference “400”)
- 0x1c: Communication component name (ws2_32.dll)
- 0x128: C2 port (443)
- 0x12c: C2 host (corp.tripswithengine[.]com)
- 0x334: C2 URI (/library/zip/)
- 0x53C: WinHttpOpen AccessType (0)
- 0x954: Proxy username (not set)
- 0xB5C: Proxy password (not set)
- 0xD64: Sleep time related (300)
- 0xD68: Sleep time related (300)
As referenced in the configuration, NeedyMantis makes use of a communication component called ws2_32.dll. This component is also stored in the custom file archive. Like the config file, the file name spoofs a Windows networking library.
This communications DLL has one export named SystemInfo. As shown below in Figure 7, SystemInfo exposes 10 functions for the main component to initiate and maintain a WebSockets connection with the C2:
Figure 7. Communications DLL API functionsThe library uses WinINet APIs for WebSockets. It also has a hard-coded user-agent of firefox/21.0.
We have also spotted a second version of the communications DLL in a file archive. It implements the same communications API but uses Libwebsockets (LWS) instead of WinINet.
Command and controlThe initial C2 beacon is an HTTPS GET request, similar to Figure 8 below:
Figure 8. Initial C2 HTTPS GET requestThe Set-Cookie header contains system information. The header value can be Base64-decoded and RtlDecompressBuffer decompressed. Once decompressed it contains a JSON object. The key values are:
- c – Computer name
- u – Username
- o – Base64-encoded data, once decoded it contains line separated “: ” entries
- p – Process name
- pa – Parent process
- f – Files in ProgramFiles directory
- p – Process list
The connection is then converted to WebSockets and a binary C2 protocol is continued. The binary protocol is separated into a header and optional data components. The 44-byte header includes the following fields:
- 0x00: 16-byte XOR key
- 0x10: Uncompressed data length
- 0x14: Compressed data length
- 0x18: Command number
- 0x28: Data length
- 0x2c: Optional data
A 16-byte random XOR key is generated and the header is XOR-encoded, starting at offset 0x18. If there is any data, it is compressed with RtlCompressBuffer and optionally encrypted with RC4.
The initial messages of the binary protocol are a key exchange with the C2 server. The protocol is performed as such:
- 32-bytes are received from the C2 server, but then ignored
- A 1024-byte random buffer is created
- The first 32-bytes of this random buffer are used as the RC4 key for further communications
- A 256-byte buffer is created that starts with google.com followed by random bytes
- The 256-byte buffer is RC4 encrypted
- A random length between 292 and 1282 is picked
- The C2 protocol message data is structured as such:
- 0x00: The random length
- 0x04: RC4 encrypted google.com buffer
- 0x104: The random 1024-byte buffer used to create the RC4 key (at least 32 bytes of it)
- This message data is compressed, but not RC4 encrypted
- A random command number between 1 and 45 is chosen
- The C2 server uses the buffer at offset 0x104 to recreate the RC4 key and presumably checks the RC4 encrypted google.com buffer
- The server sends back the random command number as an acknowledgement
The main component only has a handful of commands. Commands sent to the C2 include:
- 1110 – Sends computer name and username
- 1112 – Sends a hard-coded identifier (like 20001)
- 1150 – Keep alive
Commands received from the C2 include:
- 1020 – Load module
- 1030 – Unload module
- 1050 / 1150 – Dispatch data to module
- 1070 – Turn off active flags
The main component’s load, unload, and data dispatch commands show that NeedyMantis can extend its functionality through additional modules, but the capabilities of those modules remain unconfirmed.
Mitigation and protection guidanceMicrosoft recommends the following mitigations to reduce the impact of this threat.
- Look for outbound connections in network egress traffic to corp.tripswithengine[.]com.
- Turn on cloud-delivered protection and block at first sight to rapidly identify and block new and unknown malware variants.
- Run Endpoint Detection and Response (EDR) in block mode so that Microsoft Defender for Endpoint can block malicious artifacts, even when your non-Microsoft antivirus does not detect the threat or when Microsoft Defender Antivirus is running in passive mode. EDR in block mode works behind the scenes to remediate malicious artifacts that are detected post-breach.
- Enable network protection in Microsoft Defender for Endpoint.
- Configure automatic attack disruption in Microsoft Defender XDR. Automatic attack disruption is designed to contain attacks in progress, limit the impact on an organization’s assets, and provide more time for security teams to remediate the attack fully.
- Microsoft Defender XDR customers can turn on the following attack surface reduction rules to prevent common attack techniques used by threat actors.
You can assess how an attack surface reduction rule might impact your network by opening the security recommendation for that rule in threat and vulnerability management. In the recommendation details pane, check the user impact to determine what percentage of your devices can accept a new policy enabling the rule in blocking mode without adverse impact to user productivity.
Microsoft Defender detectionsMicrosoft Defender customers can refer to the list of applicable detections below. Microsoft Defender coordinates detection, prevention, investigation, and response across endpoints, identities, email, apps to provide integrated protection against attacks like the threat discussed in this blog.
Tactic Observed activity Microsoft Defender coverage ExecutionShellcode loading, DLL sideloading, decryption, and decompressionMicrosoft Defender for Endpoint– Suspicious DLL loaded
– An executable file loaded an unexpected DLL file
– Suspicious decode command
Microsoft Defender Antivirus
– TrojanDropper:Win64/NeedyMantisExecutionHands-on-keyboard leveraging Impacket tool for follow-on activityMicrosoft Defender for Endpoint
– Ongoing hands-on-keyboard attack via Impacket toolkit
– Impacket toolkit
– Impacket module execution
Microsoft Defender Antivirus
– HackTool:Win32/ImpacketExecutionStorm-3069 threat actor TTPsMicrosoft Defender for Endpoint
– Suspicious activity linked to an emerging threat actor has been detectedCommand and controlNetwork connectivity to NeedyMantis infrastructureMicrosoft Defender Antivirus
– Behavior:Win64/NeedyMantis Microsoft Security Copilot
Microsoft Security Copilot is embedded in Microsoft Defender and provides security teams with AI-powered capabilities to summarize incidents, analyze files and scripts, summarize identities, use guided responses, and generate device summaries, hunting queries, and incident reports.
Customers can also deploy AI agents, including the following Microsoft Security Copilot agents, to perform security tasks efficiently:
- Threat Intelligence Briefing agent
- Phishing Triage agent
- Threat Hunting agent
- Dynamic Threat Detection agent
Security Copilot is also available as a standalone experience where customers can perform specific security-related tasks, such as incident investigation, user analysis, and vulnerability impact assessment. In addition, Security Copilot offers developer scenarios that allow customers to build, test, publish, and integrate AI agents and plugins to meet unique security needs.
Threat intelligence reportsMicrosoft Defender XDR customers can use the following threat analytics reports in the Defender portal (requires license for at least one Defender XDR product) to get the most up-to-date information about the threat actor, malicious activity, and techniques discussed in this blog. These reports provide the intelligence, protection information, and recommended actions to prevent, mitigate, or respond to associated threats found in customer environments.
Microsoft Security Copilot customers can also use the Microsoft Security Copilot integration in Microsoft Defender Threat Intelligence, either in the Security Copilot standalone portal or in the embedded experience in the Microsoft Defender portal to get more information about this malware and associated activity.
Hunting queries Microsoft Defender XDRMicrosoft Defender XDR customers can run the following advanced hunting queries to find related activity in their networks:
NeedyMantis masquerading as software
A listing of legitimate, unmodified application folders, along with malicious replacement DLL filenames sideloaded by NeedyMantis.
DeviceFileEvents | where Timestamp > ago(7d) | where ( (FolderPath matches regex @"^[A-Za-z]:\\Program Files\\Poedit" and FileName == "WinSparkle.dll") or (FolderPath matches regex @"^[A-Za-z]:\\Program Files \(x86\)\\Poedit" and FileName == "WinSparkle.dll") or (FolderPath matches regex @"^[A-Za-z]:\\ProgramData\\USOShared" and FileName == "libcurl.dll") or (FolderPath matches regex @"^[A-Za-z]:\\ProgramData\\VIM" and FileName == "vim64.dll") or (FolderPath matches regex @"^[A-Za-z]:\\ProgramData\\TightVNC\\VIM" and FileName == "vim64.dll") or (FolderPath matches regex @"^[A-Za-z]:\\ProgramData\\office" and FileName == "dbghelp.dll") or (FolderPath matches regex @"^[A-Za-z]:\\ProgramData\\broadcom" and FileName == "dbghelp.dll") or (FolderPath matches regex @"^[A-Za-z]:\\ProgramData\\Intel" and FileName == "jli.dll") or (FolderPath matches regex @"^[A-Za-z]:\\Program Files\\modifiable" and FileName == "nvml.dll") or (FolderPath matches regex @"^[A-Za-z]:\\Program Files \(x86\)\\modifiable" and FileName == "nvml.dll") or (FolderPath matches regex @"^[A-Za-z]:\\ProgramData\\ics" and FileName == "nvml.dll") ) | project Timestamp, DeviceId, DeviceName, ActionType, FolderPath, FileName, SHA1, SHA256, MD5, InitiatingProcessAccountDomain, InitiatingProcessAccountName, InitiatingProcessAccountSid, InitiatingProcessAccountUpn, InitiatingProcessMD5, InitiatingProcessSHA1, InitiatingProcessSHA256, InitiatingProcessFolderPath, InitiatingProcessFileName, InitiatingProcessCommandLine, InitiatingProcessCreationTime, ReportId, TenantIdNeedyMantis C2
This query identifies connectivity to the NeedyMantis command and control site for this activity.
search in (DeviceNetworkEvents, EmailUrlInfo, UrlClickEvents, DeviceEvents, DeviceFileEvents, DeviceProcessEvents) "corp.tripswithengine.com" | where Timestamp > ago(7d) | extend SourceTable = $table | project Timestamp, DeviceName, InitiatingProcessAccountName, InitiatingProcessAccountUpn, AccountName, AccountUpn, RemoteIP, LocalIP, IPAddress, RemoteUrl, Url, UrlDomain, FileOriginUrl, FileOriginReferrerUrl, FileOriginIP, ProcessCommandLine, InitiatingProcessCommandLine, InitiatingProcessFileName, FileName, FolderPath, NetworkMessageId, SourceTableNeedyMantis communications DLL hard-coded user-agent
Identify connectivity utilizing the NeedyMantis hard-coded user-agent.
search in (DeviceNetworkEvents, DeviceEvents, UrlClickEvents, EmailUrlInfo) "Firefox/21.0" | where Timestamp > ago(7d) | extend SourceTable = $table | project Timestamp, DeviceName = iff(isnull(DeviceName), "", DeviceName), AccountUpn = coalesce(InitiatingProcessAccountUpn, AccountUpn, ""), AccountName = coalesce(InitiatingProcessAccountName, AccountName, ""), RemoteIP = coalesce(RemoteIP, IPAddress, ""), Url = coalesce(RemoteUrl, Url, ""), UserAgent = AdditionalFields, SourceTable Microsoft SentinelMicrosoft Sentinel customers can use the TI Mapping analytics (a series of analytics all prefixed with ‘TI map’) to automatically match the malicious domain indicators mentioned in this blog post with data in their workspace. If the TI Map analytics are not currently deployed, customers can install the Threat Intelligence solution from the Microsoft Sentinel Content Hub to have the analytics rule deployed in their Sentinel workspace.
NeedyMantis C2
This query identifies connectivity to the NeedyMantis command and control site for this activity.
search in (CommonSecurityLog, SecurityEvent, AzureDiagnostics) "corp.tripswithengine.com" | where TimeGenerated > ago(7d) | project TimeGenerated, DeviceName, Computer, SourceIP, SourcePort, SourceUserName, DestinationIP, DestinationPort, DestinationHostName, DestinationDnsDomain, RequestURL, ProcessName, DestinationUserName, SourceHostName, Message, $tableNeedyMantis communications DLL hard-code user-agent
Identify connectivity utilizing the NeedyMantis hard-code user-agent.
CommonSecurityLog | where TimeGenerated > ago(7d) | where RequestClientApplication contains "Firefox/21.0" or Message contains "Firefox/21.0" | project TimeGenerated, DeviceName, SourceUserName, SourceIP, DestinationIP, RequestURL, RequestClientApplication Indicators of compromise IndicatorTypeDescriptionFirst seenLast seene842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e SHA-256First-stage loader WinSparkle.dll 2026-05-21 2026-05-219cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077efSHA-256Custom file archive WinSparkle 2026-05-23 2026-05-23c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77SHA-256Custom file archive libcurl2025-10-032025-10-03corp.tripswithengine[.]comHost nameC2 host name References Learn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.
To get notified about new publications and to join discussions on social media, follow us on LinkedIn, X (formerly Twitter), and Bluesky.
To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the Microsoft Threat Intelligence podcast.
The post NeedyMantis: Unpacking a post-compromise malware family used in targeted operations appeared first on Microsoft Security Blog.
