Threat reportMalwareTL-2026-2733

NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operations

highACTIVE

NeedyMantis: Storm-3069 Post-Compromise Modular Malware in (TL-2026-2733) is a high-severity malware campaign, first published 2026-09-28 and last reviewed 2026-09-29. It is attributed to Storm-3069 (China) with low confidence, affects Poedit Poedit (WinSparkle update library), maps to 24 MITRE ATT&CK techniques (T1021.002, T1027, T1027.007), and is covered by 9 detection rules and 42 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
24MITRE ATT&CK
Actors
1Storm-3069
Detection rules
9SPL · KQL · Sigma
IOCs
42Indicators of compromise

Key facts for TL-2026-2733

Threat ID
TL-2026-2733
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Storm-3069
Attribution confidence
LOW
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
telecoms, higher education, medical nonprofit, intergovernmental organization, government contractor
Detection rules
9
Indicators of compromise
42
Updates
2026-09-29 · 3 updates · revalidated 3× · latest source

Malware and tooling in NeedyMantis: Storm-3069 Post-Compromise Modular Malware in

Malware and tooling: Behavior:Win64/NeedyMantis, NeedyMantis, Storm, TrojanDropper:Win64/NeedyMantis, Impacket - S0357, TightVNC

How NeedyMantis: Storm-3069 Post-Compromise Modular Malware in works

Microsoft (MSTIC) details NeedyMantis, a modular post-compromise malware family attributed to activity cluster Storm-3069, deployed via DLL sideloading of legitimate software (Poedit, curl, Vim, TightVNC) after initial access is already established. The malware uses a multi-stage loader chain, a custom encrypted archive format, and WebSocket-based C2 with RC4-encrypted, RtlCompressBuffer-compressed traffic, and has been observed against telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors since at least October 2025.

NeedyMantis is a modular post-compromise malware family that Microsoft Threat Intelligence attributes to an activity cluster it tracks as Storm-3069. Microsoft states the activity 'aligns with threat actors operating from China' but explicitly has 'not attributed Storm-3069 to a Chinese nation-state actor.' Deployment is strictly post-compromise: in observed intrusions, operators already possessing environment access used the Impacket toolkit during hands-on-keyboard activity to copy a legitimate application, a malicious DLL, and a custom encrypted file archive onto the target host, triggering DLL side-loading. Observed carrier applications include Poedit (WinSparkle.dll), curl (libcurl.dll), Vim and TightVNC (vim64.dll), and components branded to resemble Microsoft Office, Broadcom, Intel, and NVIDIA software (dbghelp.dll, jli.dll, nvml.dll).

The infection chain runs in three stages. The first-stage loader DLL uses obfuscated stack strings and mathematically-obfuscated constants to hide Windows API/DLL references, checks ProcessDebugFlags and ThreadHideFromDebugger to detect debuggers, and extracts a second-stage loader from the accompanying custom file archive. The second-stage loader carries a .ps1 extension but is actually x64 shellcode: it decodes and decompresses an embedded binary using a configurable ROR (rotate-right) algorithm and resolves Windows APIs via hash values rather than plaintext imports, ultimately executing a minimized custom PE format. The third stage is the main component, which creates a mutex of the form '<username>-<process name>' (e.g., 'Contoso-Poedit.exe'), loads a configuration module masquerading as dnsapi.dll (a 3448-byte structure holding the C2 host, port 443, URI /library/zip/, a 300-second sleep timer, and proxy-credential fields), and a communications module masquerading as ws2_32.dll that establishes and maintains a WebSocket session (two implementation variants exist: WinINet-based and Libwebsockets-based) using the hard-coded user-agent 'firefox/21.0'.

Initial contact is an HTTPS GET whose response Set-Cookie header carries a Base64-encoded, RtlDecompressBuffer-decompressed JSON blob of host reconnaissance data (computer name, username, process name, parent process, file listing, process list) before the session upgrades to WebSocket. Post-upgrade traffic uses a 44-byte binary frame header (16-byte XOR key, uncompressed/compressed length fields, a command number, and a data-length field) with RtlCompressBuffer compression and optional RC4 encryption. Key exchange has the implant generate a 1024-byte random buffer, take its first 32 bytes as an RC4 key, and send a 256-byte RC4-encrypted buffer beginning with the string 'google.com' plus random padding (length randomized 292-1282 bytes) so the C2 server can rederive and validate the key before acknowledging with a random command number. The command set includes outbound codes 1110 (send computer/username), 1112 (send a hard-coded identifier), and 1150 (keep-alive), and inbound codes 1020/1030 (load/unload module), 1050/1150 (dispatch data to a loaded module), and 1070 (clear active flags) — implementing NeedyMantis's plugin-style extensibility.

The custom file archive format itself is XOR-encoded at the outer layer and RtlDecompressBuffer-decompressed, with individual entries XOR-decoded by filename and separately decompressed. One recovered WinSparkle-themed archive bundled legitimate 7-Zip and Sysinternals components alongside the malicious dnsapi.dll (config), ws2_32.dll (comms), and msvcrt140.dll (shellcode loader) modules; a second, libcurl-themed archive variant instead bundled 300.c (config), 300.s (comms), an 'is' file implementing persistence via a Windows Services module, and 'm.l' (main component) — indicating the module naming/format has evolved across samples collected between October 2025 and May 2026.

Microsoft explicitly states it has not observed NeedyMantis itself distributed via a supply-chain compromise, but notes Storm-3069 was originally identified by pivoting off Kaspersky's May 2026 report of a supply-chain compromise of the DAEMON Tools installer (trojanized from 2026-04-08, publicly disclosed and patched 2026-05-06), which Kaspersky found to contain Chinese-language artifacts. Microsoft frames the supply-chain compromise as 'one possible means by which an actor could gain the access necessary to deploy the malware' rather than a confirmed distribution vector for NeedyMantis, so the DAEMON Tools IOCs below are recorded as related pivot-source infrastructure, not confirmed NeedyMantis infrastructure.

MITRE ATT&CK techniques used in TL-2026-2733

Lateral Movement

T1021.002 Remote Services: SMB/Windows Admin Shares; T1570 Lateral Tool Transfer

Defense Evasion

T1027 Obfuscated Files or Information; T1027.007 Obfuscated Files or Information: Dynamic API Resolution; T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1574.001 DLL; T1622 Debugger Evasion

Discovery

T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery

Execution

T1059.001 PowerShell; T1129 Shared Modules; T1569.002 System Services: Service Execution

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer; T1132.001 Data Encoding: Standard Encoding; T1573.001 Encrypted Channel: Symmetric Cryptography

Initial Access

T1195.002 Supply Chain Compromise: Compromise Software Supply Chain

Persistence

T1543.003 Create or Modify System Process: Windows Service; T1574.002 Hijack Execution Flow: DLL Side-Loading

Collection

T1560.003 Archive Collected Data: Archive via Custom Method

Affected products and versions in NeedyMantis: Storm-3069 Post-Compromise Modular Malware in

  • Poedit — Poedit (WinSparkle update library)
    Vulnerable versions: unspecified - abused as a DLL side-loading carrier, not a code vulnerability
    Fixed in: N/A
  • curl project — curl (libcurl.dll)
    Vulnerable versions: unspecified - abused as a DLL side-loading carrier
    Fixed in: N/A
  • Vim / TightVNC — Vim, TightVNC (vim64.dll)
    Vulnerable versions: unspecified - abused as a DLL side-loading carrier
    Fixed in: N/A
  • Multiple (Microsoft Office, Broadcom, Intel, NVIDIA components) — dbghelp.dll, jli.dll, nvml.dll host applications
    Vulnerable versions: unspecified - abused as DLL side-loading carriers
    Fixed in: N/A

Remediation for NeedyMantis: Storm-3069 Post-Compromise Modular Malware in

Immediate actions

  • Hunt for Microsoft Defender detections TrojanDropper:Win64/NeedyMantis, Behavior:Win64/NeedyMantis, and HackTool:Win32/Impacket across the environment
  • Block and alert on network connections to corp.tripswithengine.com and the /library/zip/ URI on port 443
  • Inventory installations of Poedit, curl, Vim, and TightVNC for co-located DLLs (WinSparkle.dll, libcurl.dll, vim64.dll, dbghelp.dll, jli.dll, nvml.dll) that do not match expected vendor file hashes

Workarounds

  • Where DAEMON Tools is deployed, confirm it is updated to version 12.6.0.2445 or later to remediate the related Kaspersky-reported supply-chain backdoor (patched 2026-05-06)

Longer-term hardening

  • Deploy EDR detections for suspicious DLL loading and unexpected DLL files alongside known-good application binaries
  • Monitor and restrict hands-on-keyboard use of Impacket-family remote-execution tooling on the network
  • Apply application allow-listing and code-signing enforcement to reduce exposure to DLL search-order side-loading

Timeline of NeedyMantis: Storm-3069 Post-Compromise Modular Malware in

  • Earliest known NeedyMantis sample: libcurl-themed custom archive (SHA-256 c82520eb...) first seen
  • Storm-3069 typosquat domain env-check.daemontools.cc, tied to the DAEMON Tools supply-chain compromise that later led Microsoft to discover NeedyMantis, is registered.
  • DAEMON Tools installer trojanization begins (Kaspersky-reported), later cited by Microsoft as the pivot source for identifying Storm-3069 activity
  • Distribution window of the trojanized DAEMON Tools Lite installers ends (Kaspersky); fixed release 12.6.0.2445 follows disclosure.
  • Kaspersky publicly discloses the DAEMON Tools supply-chain backdoor; vendor ships patched build 12.6.0.2445
  • Disc Soft Limited acknowledges the supply-chain compromise of its DAEMON Tools Lite installers.
  • First-stage loader (WinSparkle.dll, SHA-256 e842dd76...) first seen
  • Custom archive, WinSparkle-themed variant (SHA-256 9cb68f98...) first seen
  • Mandiant/Google publish campaign 26-054 describing UNC6863 (suspected China-nexus) deploying SLICKDEMON, BADFALL and QUIC RAT via the DAEMON Tools compromise; a further validation content update follows June 24, 2026.
  • Microsoft (MSTIC) publishes NeedyMantis analysis, attributing the activity cluster to Storm-3069

Update history for TL-2026-2733

Sources cited for NeedyMantis: Storm-3069 Post-Compromise Modular Malware in

Detection coverage for TL-2026-2733

As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2733 across Splunk SPL, Microsoft KQL and Sigma, covering 42 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
42 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-2733

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats