Executive Summary
Microsoft identified NeedyMantis, a sophisticated malware family used by Storm-3069 (suspected China-nexus threat actor) to maintain persistent access in targeted networks since October 2025. The malware employs DLL sideloading techniques with legitimate programs like Poedit, curl, and TightVNC to establish covert command-and-control channels via HTTPS and WebSocket connections. Organizations affected include telecommunications companies, universities, medical nonprofits, intergovernmental organizations, and government contractors, with the campaign linked to the DAEMON Tools supply chain compromise discovered in May 2026.
This incident highlights the growing sophistication of state-sponsored APT groups leveraging supply chain attacks and living-off-the-land techniques to achieve long-term persistence. The campaign demonstrates how threat actors are increasingly targeting critical infrastructure and sensitive sectors through legitimate software channels.
Why This Matters Now
Nation-state actors are escalating supply chain compromises and persistence techniques targeting critical infrastructure. Organizations must implement zero-trust segmentation and enhanced egress monitoring to detect and prevent long-term APT campaigns before data exfiltration occurs.
Attack Path Analysis
Storm-3069 (China-nexus threat actor) initially compromised networks through supply chain attacks like DAEMON Tools, then deployed NeedyMantis malware via DLL sideloading for persistence. Attackers used Impacket toolkit for lateral movement across network shares, established HTTPS/WebSocket C2 communications, and maintained long-term access to exfiltrate sensitive data from telecommunications, government, and healthcare organizations.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Supply chain compromise of DAEMON Tools Lite installers (April-May 2026) delivered initial access, with legitimate signed installers carrying malicious code targeting telecommunications and government organizations
MITRE ATT&CK® Techniques
Hijack Execution Flow: DLL Side-Loading
Obfuscated Files or Information: Embedded Payloads
Application Layer Protocol: Web Protocols
Encrypted Channel: Asymmetric Cryptography
Boot or Logon Autostart Execution: Shortcut Modification
Ingress Tool Transfer
Masquerading: Match Legitimate Name or Location
File and Directory Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Network Segmentation and Monitoring
Control ID: 11.3.2
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 9
CISA ZTMM 2.0 – Identity and Access Management
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Management of Technical Vulnerabilities
Control ID: A.8.16
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Directly targeted by NeedyMantis APT with lateral movement capabilities, requiring east-west traffic security and encrypted communications to prevent long-term network compromise.
Higher Education/Acadamia
Universities specifically targeted by Storm-3069 operations, vulnerable to DLL sideloading attacks requiring zero trust segmentation and enhanced endpoint protection measures.
Health Care / Life Sciences
Medical nonprofits targeted with persistent access malware, critical HIPAA compliance violations through unencrypted traffic and inadequate egress security controls implementation.
Government Administration
Government contractors compromised by Chinese-nexus actors, demanding multicloud visibility controls and threat detection capabilities to prevent sustained APT infiltration activities.
Sources
- Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networkshttps://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.htmlVerified
- NeedyMantis: Unpacking a post-compromise malware family used in targeted operationshttps://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/Verified
- DAEMON Tools Supply Chain Attack Analysishttps://thehackernews.com/2026/05/daemon-tools-supply-chain-attack.htmlVerified
- Google Cloud Threat Intelligence - Mitigation Guidance for Supply Chain Compromisehttps://cloud.google.com/blog/topics/threat-intelligence/mitigation-guidance-for-supply-chain-compromiseVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain Storm-3069's lateral movement and data exfiltration by implementing workload segmentation and controlled egress policies. The attacker's ability to spread across network shares and establish persistent C2 channels would be significantly reduced through east-west traffic controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial compromise through supply chain attack would likely succeed, but subsequent malware deployment scope could be constrained through workload isolation and reduced network reachability to critical assets.
Control: Zero Trust Segmentation
Mitigation: DLL sideloading privilege escalation would likely succeed on compromised endpoints, but elevated access scope could be constrained through identity-aware segmentation limiting reachability to sensitive workloads and data stores.
Control: East-West Traffic Security
Mitigation: Lateral movement using Impacket toolkit would likely be significantly constrained as east-west traffic controls could block unauthorized SMB connections and file transfers between network segments containing the malware bundles.
Control: Multicloud Visibility & Control
Mitigation: C2 communications to external domains would likely be detected and constrained through centralized visibility controls that monitor cross-cloud traffic patterns and identify suspicious outbound connection behaviors across the infrastructure.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration operations would likely be constrained through controlled egress policies that limit outbound data transfers and monitor suspicious traffic volumes from sensitive workloads to external destinations.
While some intelligence gathering might still occur, the overall impact scope would likely be significantly reduced with attackers constrained to isolated network segments and limited data access compared to unrestricted lateral movement.
Impact at a Glance
Affected Business Functions
- Network Security Operations
- IT Infrastructure Management
- Data Protection and Privacy
- Business Continuity Operations
Estimated downtime: 7 days
Estimated loss: $250,000
Potential access to sensitive organizational data across telecommunications networks, university research data, medical nonprofit patient information, intergovernmental communications, and government contractor classified or sensitive materials. Long-term persistent access enables extensive data exfiltration over months.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Zero Trust Segmentation with identity-based policies to prevent lateral movement via Impacket toolkit across network shares
- • Implement Egress Security & Policy Enforcement to block unauthorized C2 communications to domains like corp.tripswithengine[.]com
- • Enable Multicloud Visibility & Control to detect suspicious WebSocket connections and anomalous DLL sideloading activities
- • Configure Threat Detection & Anomaly Response to identify persistent access patterns and modular malware deployment behaviors
- • Establish East-West Traffic Security monitoring to detect and block internal propagation of malicious payloads between workloads



