malware
Published 2026-09-28
Verified 2026-09-29

Microsoft NeedyMantis (28 Sep): modular post-compromise malware — Storm-3069 / DAEMON Tools pivot; telecom & contractor targets

Microsoft Threat Intelligence (published 28 September 2026; Cyber Security News amplified same day) documents NeedyMantis, a modular post-compromise malware family used in a limited number of targeted operations against telecommunications organisations, universities, medical nonprofits, intergovernmental bodies, and government contractors. Typically deployed after initial access is already established; activity dates to at least October 2025. Microsoft identified the family while pivoting from IoCs tied to Kaspersky’s DAEMON Tools supply-chain investigation. Observed operator: Storm-3069 (Microsoft designator for DAEMON Tools-linked activity; assessed China-origin but not attributed as a Chinese nation-state actor). Microsoft has also seen NeedyMantis beyond Storm-3069, so more than one operator may have access. Architecture: C++/x64 shellcode multi-stage loaders, custom encrypted/compressed archives, DLL sideloading via abused legitimate apps (Poedit/WinSparkle, curl/libcurl, Vim, TightVNC) and spoofed Office/Broadcom/Intel/NVIDIA DLL paths; WebSockets C2 (hard-coded UA including Firefox/21.0); modular components for long-term access. Example C2 host: corp.tripswithengine[.]com. Impacket used in at least one hands-on-keyboard copy/exec from a network share. No product CVE. Primary: Microsoft Security Blog; wire: Cyber Security News 28 Sep.

Product
NeedyMantis (Windows post-compromise malware framework; Storm-3069 and possibly other operators)
Versions
n/a (malware family; activity since ≥ Oct 2025; no product CVE). Sample IoCs in Microsoft blog include WinSparkle.dll SHA-256 e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e and C2 corp.tripswithengine[.]com
Exploited in Australia?
unknown
Patch to
Hunt DLL sideload paths (Poedit/WinSparkle, libcurl, vim64, TightVNC, spoofed dbghelp/jli/nvml under ProgramData/ProgramFiles); egress to corp.tripswithengine[.]com and hard-coded Firefox/21.0 UA; enable cloud-delivered protection / block-at-first-sight; run Microsoft Defender for Endpoint EDR in block mode; apply Microsoft hunting queries and IoCs from the blog; review Impacket lateral-copy artifacts. Kaspersky DAEMON Tools supply-chain reporting remains relevant for Storm-3069 initial-access context.

Primary: Microsoft Security Blog — NeedyMantis post-compromise malware (28 Sep 2026) · Vendor: Microsoft Threat Intelligence — NeedyMantis / Storm-3069 · Cyber Security News — NeedyMantis covert access summary (28 Sep 2026)

breaches identity network