NeedyMantis custom archive extraction with disguised staged files
Detects NeedyMantis malware loader components that utilize the RtlDecompressBuffer API for custom XOR-compressed archive extraction. The rule specifically looks for the presence of known staged file names (dnsapi.dll, ws2_32.dll, msvcrt140.dll, or encryptbase64.ps1) alongside decoy file references typically used by the threat actor.
YARA

