The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

Microsoft Threat Intelligence discovered NeedyMantis, a sophisticated modular malware family used in targeted operations against telecommunications organizations, universities, medical nonprofits, and government contractors since October 2025. The malware, deployed by China-linked threat actor Storm-3069 and potentially others, employs advanced evasion techniques including custom encrypted archives, multiple loaders, and DLL sideloading to maintain persistent access in victim environments. NeedyMantis represents a concerning evolution in post-compromise tooling, combining multiple layers of obfuscation with modular architecture that enables operators to extend functionality and evade detection across diverse target environments.

Why This Matters Now

The discovery of NeedyMantis highlights the growing sophistication of state-sponsored malware targeting critical infrastructure and sensitive organizations, with its modular design enabling prolonged undetected access for espionage operations.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

NeedyMantis combines multiple sophisticated evasion techniques including custom encrypted archives, modular architecture, and DLL sideloading, making it extremely difficult to detect and analyze while providing persistent access to victim networks.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely constrain NeedyMantis operators by limiting lateral movement paths and reducing blast radius through workload segmentation. The segmented network architecture could significantly reduce attacker reachability across telecommunications and government contractor environments.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Zero Trust architecture would likely limit the scope of initial compromise by restricting workload-to-workload communication and reducing the blast radius from compromised endpoints.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Microsegmentation policies would likely restrict the effective privilege scope by limiting access to resources based on workload identity rather than inherited application permissions.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic enforcement would likely constrain lateral movement by blocking unauthorized network share access and restricting workload-to-workload communication paths across the environment.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Centralized visibility would likely detect and constrain C2 traffic patterns by monitoring east-west and north-south communications across multicloud environments for unauthorized external connections.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress controls would likely constrain data exfiltration by limiting outbound communication paths and enforcing policies that restrict unauthorized data transmission through HTTP headers.

Impact (Mitigations)

Residual exposure would likely be constrained to initially compromised workloads with reduced ability to expand operations across telecommunications and government contractor infrastructure.

Impact at a Glance

Affected Business Functions

  • Network Operations
  • Telecommunications Infrastructure
  • Academic Research Operations
  • Government Contract Services
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive organizational data including telecommunications infrastructure details, academic research data, medical nonprofit patient information, and government contractor proprietary information through long-term persistent access and data exfiltration capabilities

Recommended Actions

  • • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement via Impacket toolkit and limit blast radius of post-compromise activity
  • • Deploy Egress Security & Policy Enforcement to block unauthorized C2 communications to domains like corp.tripswithengine[.]com and detect WebSockets traffic anomalies
  • • Enable East-West Traffic Security monitoring to detect internal propagation of malware components and hands-on-keyboard activity across network shares
  • • Activate Multicloud Visibility & Control with anomaly detection to identify suspicious DLL sideloading, process injection, and encrypted C2 communication patterns
  • • Deploy Threat Detection & Anomaly Response capabilities to baseline normal application behavior and alert on legitimate software abuse and covert remote access tools

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image