NeedyMantis DLL Sideload via Trojanized Update Component in Legit App

Detects NeedyMantis first-stage loader activity where a legitimate application (e.g., Poedit, curl, Vim, TightVNC) is executed to load an update or support DLL from a non-standard staging path (e.g., %ProgramData% subdirectories), followed by the presence of a co-located encrypted second-stage archive.