The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

Microsoft identified NeedyMantis, a sophisticated malware family used by Storm-3069 (suspected China-nexus threat actor) to maintain persistent access in targeted networks since October 2025. The malware employs DLL sideloading techniques with legitimate programs like Poedit, curl, and TightVNC to establish covert command-and-control channels via HTTPS and WebSocket connections. Organizations affected include telecommunications companies, universities, medical nonprofits, intergovernmental organizations, and government contractors, with the campaign linked to the DAEMON Tools supply chain compromise discovered in May 2026.

This incident highlights the growing sophistication of state-sponsored APT groups leveraging supply chain attacks and living-off-the-land techniques to achieve long-term persistence. The campaign demonstrates how threat actors are increasingly targeting critical infrastructure and sensitive sectors through legitimate software channels.

Why This Matters Now

Nation-state actors are escalating supply chain compromises and persistence techniques targeting critical infrastructure. Organizations must implement zero-trust segmentation and enhanced egress monitoring to detect and prevent long-term APT campaigns before data exfiltration occurs.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

NeedyMantis uses DLL sideloading with legitimate programs like Poedit and TightVNC, loading malicious DLLs that establish encrypted command-and-control channels via HTTPS and WebSocket connections.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely constrain Storm-3069's lateral movement and data exfiltration by implementing workload segmentation and controlled egress policies. The attacker's ability to spread across network shares and establish persistent C2 channels would be significantly reduced through east-west traffic controls.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Initial compromise through supply chain attack would likely succeed, but subsequent malware deployment scope could be constrained through workload isolation and reduced network reachability to critical assets.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: DLL sideloading privilege escalation would likely succeed on compromised endpoints, but elevated access scope could be constrained through identity-aware segmentation limiting reachability to sensitive workloads and data stores.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement using Impacket toolkit would likely be significantly constrained as east-west traffic controls could block unauthorized SMB connections and file transfers between network segments containing the malware bundles.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: C2 communications to external domains would likely be detected and constrained through centralized visibility controls that monitor cross-cloud traffic patterns and identify suspicious outbound connection behaviors across the infrastructure.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration operations would likely be constrained through controlled egress policies that limit outbound data transfers and monitor suspicious traffic volumes from sensitive workloads to external destinations.

Impact (Mitigations)

While some intelligence gathering might still occur, the overall impact scope would likely be significantly reduced with attackers constrained to isolated network segments and limited data access compared to unrestricted lateral movement.

Impact at a Glance

Affected Business Functions

  • Network Security Operations
  • IT Infrastructure Management
  • Data Protection and Privacy
  • Business Continuity Operations
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $250,000

Data Exposure

Potential access to sensitive organizational data across telecommunications networks, university research data, medical nonprofit patient information, intergovernmental communications, and government contractor classified or sensitive materials. Long-term persistent access enables extensive data exfiltration over months.

Recommended Actions

  • • Deploy Zero Trust Segmentation with identity-based policies to prevent lateral movement via Impacket toolkit across network shares
  • • Implement Egress Security & Policy Enforcement to block unauthorized C2 communications to domains like corp.tripswithengine[.]com
  • • Enable Multicloud Visibility & Control to detect suspicious WebSocket connections and anomalous DLL sideloading activities
  • • Configure Threat Detection & Anomaly Response to identify persistent access patterns and modular malware deployment behaviors
  • • Establish East-West Traffic Security monitoring to detect and block internal propagation of malicious payloads between workloads

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image