Executive Summary
Microsoft Threat Intelligence discovered NeedyMantis, a sophisticated modular malware family used in targeted operations against telecommunications organizations, universities, medical nonprofits, and government contractors since October 2025. The malware, deployed by China-linked threat actor Storm-3069 and potentially others, employs advanced evasion techniques including custom encrypted archives, multiple loaders, and DLL sideloading to maintain persistent access in victim environments. NeedyMantis represents a concerning evolution in post-compromise tooling, combining multiple layers of obfuscation with modular architecture that enables operators to extend functionality and evade detection across diverse target environments.
Why This Matters Now
The discovery of NeedyMantis highlights the growing sophistication of state-sponsored malware targeting critical infrastructure and sensitive organizations, with its modular design enabling prolonged undetected access for espionage operations.
Attack Path Analysis
NeedyMantis represents a sophisticated post-compromise malware family used by China-associated threat actors including Storm-3069. The attack begins after initial environment access, deploys through DLL sideloading with legitimate software, establishes persistent command and control via WebSockets over HTTPS, enables modular functionality for extended operations, exfiltrates system information and supports follow-on data theft, and maintains long-term access for sustained espionage operations targeting telecommunications, government contractors, and critical infrastructure.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Threat actors gain initial access to target environment through supply chain compromise (DAEMON Tools) or other methods, then deploy NeedyMantis as post-compromise malware via DLL sideloading with legitimate software packages
MITRE ATT&CK® Techniques
Hijack Execution Flow: DLL Side-Loading
Obfuscated Files or Information
Process Injection
Non-Standard Port
Encrypted Channel: Symmetric Cryptography
Archive Collected Data
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Masquerading: Match Legitimate Name or Location
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Device Security and Compliance
Control ID: DevicesSec-1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
Digital Operational Resilience Act (DORA) – ICT Risk Management Framework
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
PCI DSS 4.0 – External Penetration Testing
Control ID: 11.3.1
ISO 27001 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Directly targeted by NeedyMantis APT with post-compromise malware enabling long-term access, lateral movement, and encrypted traffic exfiltration risks.
Higher Education/Acadamia
Universities specifically targeted by NeedyMantis operations requiring enhanced east-west traffic security and zero trust segmentation for research protection.
Government Administration
Government contractors affected by China-aligned APT requiring multicloud visibility, egress security enforcement, and comprehensive threat detection capabilities.
Health Care / Life Sciences
Medical nonprofits targeted with modular malware framework demanding HIPAA-compliant encrypted traffic monitoring and anomaly detection systems implementation.
Sources
- NeedyMantis: Unpacking a post-compromise malware family used in targeted operationshttps://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/Verified
- DAEMON Tools supply chain compromise investigationhttps://securelist.com/tr/daemon-tools-backdoor/119654/Verified
- Microsoft Threat Intelligence Bloghttps://www.microsoft.com/en-us/security/blog/topic/threat-intelligence/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain NeedyMantis operators by limiting lateral movement paths and reducing blast radius through workload segmentation. The segmented network architecture could significantly reduce attacker reachability across telecommunications and government contractor environments.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero Trust architecture would likely limit the scope of initial compromise by restricting workload-to-workload communication and reducing the blast radius from compromised endpoints.
Control: Zero Trust Segmentation
Mitigation: Microsegmentation policies would likely restrict the effective privilege scope by limiting access to resources based on workload identity rather than inherited application permissions.
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement would likely constrain lateral movement by blocking unauthorized network share access and restricting workload-to-workload communication paths across the environment.
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility would likely detect and constrain C2 traffic patterns by monitoring east-west and north-south communications across multicloud environments for unauthorized external connections.
Control: Egress Security & Policy Enforcement
Mitigation: Egress controls would likely constrain data exfiltration by limiting outbound communication paths and enforcing policies that restrict unauthorized data transmission through HTTP headers.
Residual exposure would likely be constrained to initially compromised workloads with reduced ability to expand operations across telecommunications and government contractor infrastructure.
Impact at a Glance
Affected Business Functions
- Network Operations
- Telecommunications Infrastructure
- Academic Research Operations
- Government Contract Services
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive organizational data including telecommunications infrastructure details, academic research data, medical nonprofit patient information, and government contractor proprietary information through long-term persistent access and data exfiltration capabilities
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement via Impacket toolkit and limit blast radius of post-compromise activity
- • Deploy Egress Security & Policy Enforcement to block unauthorized C2 communications to domains like corp.tripswithengine[.]com and detect WebSockets traffic anomalies
- • Enable East-West Traffic Security monitoring to detect internal propagation of malware components and hands-on-keyboard activity across network shares
- • Activate Multicloud Visibility & Control with anomaly detection to identify suspicious DLL sideloading, process injection, and encrypted C2 communication patterns
- • Deploy Threat Detection & Anomaly Response capabilities to baseline normal application behavior and alert on legitimate software abuse and covert remote access tools



