Threat reportMalwareTL-2026-2733
NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operations
NeedyMantis: Storm-3069 Post-Compromise Modular Malware in (TL-2026-2733) is a high-severity malware campaign, first published 2026-09-28 and last reviewed 2026-09-29. It is attributed to Storm-3069 (China) with low confidence, affects Poedit Poedit (WinSparkle update library), maps to 24 MITRE ATT&CK techniques (T1021.002, T1027, T1027.007), and is covered by 9 detection rules and 42 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 24MITRE ATT&CK
- Actors
- 1Storm-3069
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 42Indicators of compromise
Key facts for TL-2026-2733
- Threat ID
- TL-2026-2733
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Storm-3069
- Attribution confidence
- LOW
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- telecoms, higher education, medical nonprofit, intergovernmental organization, government contractor
- Detection rules
- 9
- Indicators of compromise
- 42
- Updates
- 2026-09-29 · 3 updates · revalidated 3× · latest source
Malware and tooling in NeedyMantis: Storm-3069 Post-Compromise Modular Malware in
Malware and tooling: Behavior:Win64/NeedyMantis, NeedyMantis, Storm, TrojanDropper:Win64/NeedyMantis, Impacket - S0357, TightVNC
How NeedyMantis: Storm-3069 Post-Compromise Modular Malware in works
Microsoft (MSTIC) details NeedyMantis, a modular post-compromise malware family attributed to activity cluster Storm-3069, deployed via DLL sideloading of legitimate software (Poedit, curl, Vim, TightVNC) after initial access is already established. The malware uses a multi-stage loader chain, a custom encrypted archive format, and WebSocket-based C2 with RC4-encrypted, RtlCompressBuffer-compressed traffic, and has been observed against telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors since at least October 2025.
NeedyMantis is a modular post-compromise malware family that Microsoft Threat Intelligence attributes to an activity cluster it tracks as Storm-3069. Microsoft states the activity 'aligns with threat actors operating from China' but explicitly has 'not attributed Storm-3069 to a Chinese nation-state actor.' Deployment is strictly post-compromise: in observed intrusions, operators already possessing environment access used the Impacket toolkit during hands-on-keyboard activity to copy a legitimate application, a malicious DLL, and a custom encrypted file archive onto the target host, triggering DLL side-loading. Observed carrier applications include Poedit (WinSparkle.dll), curl (libcurl.dll), Vim and TightVNC (vim64.dll), and components branded to resemble Microsoft Office, Broadcom, Intel, and NVIDIA software (dbghelp.dll, jli.dll, nvml.dll).
The infection chain runs in three stages. The first-stage loader DLL uses obfuscated stack strings and mathematically-obfuscated constants to hide Windows API/DLL references, checks ProcessDebugFlags and ThreadHideFromDebugger to detect debuggers, and extracts a second-stage loader from the accompanying custom file archive. The second-stage loader carries a .ps1 extension but is actually x64 shellcode: it decodes and decompresses an embedded binary using a configurable ROR (rotate-right) algorithm and resolves Windows APIs via hash values rather than plaintext imports, ultimately executing a minimized custom PE format. The third stage is the main component, which creates a mutex of the form '<username>-<process name>' (e.g., 'Contoso-Poedit.exe'), loads a configuration module masquerading as dnsapi.dll (a 3448-byte structure holding the C2 host, port 443, URI /library/zip/, a 300-second sleep timer, and proxy-credential fields), and a communications module masquerading as ws2_32.dll that establishes and maintains a WebSocket session (two implementation variants exist: WinINet-based and Libwebsockets-based) using the hard-coded user-agent 'firefox/21.0'.
Initial contact is an HTTPS GET whose response Set-Cookie header carries a Base64-encoded, RtlDecompressBuffer-decompressed JSON blob of host reconnaissance data (computer name, username, process name, parent process, file listing, process list) before the session upgrades to WebSocket. Post-upgrade traffic uses a 44-byte binary frame header (16-byte XOR key, uncompressed/compressed length fields, a command number, and a data-length field) with RtlCompressBuffer compression and optional RC4 encryption. Key exchange has the implant generate a 1024-byte random buffer, take its first 32 bytes as an RC4 key, and send a 256-byte RC4-encrypted buffer beginning with the string 'google.com' plus random padding (length randomized 292-1282 bytes) so the C2 server can rederive and validate the key before acknowledging with a random command number. The command set includes outbound codes 1110 (send computer/username), 1112 (send a hard-coded identifier), and 1150 (keep-alive), and inbound codes 1020/1030 (load/unload module), 1050/1150 (dispatch data to a loaded module), and 1070 (clear active flags) — implementing NeedyMantis's plugin-style extensibility.
The custom file archive format itself is XOR-encoded at the outer layer and RtlDecompressBuffer-decompressed, with individual entries XOR-decoded by filename and separately decompressed. One recovered WinSparkle-themed archive bundled legitimate 7-Zip and Sysinternals components alongside the malicious dnsapi.dll (config), ws2_32.dll (comms), and msvcrt140.dll (shellcode loader) modules; a second, libcurl-themed archive variant instead bundled 300.c (config), 300.s (comms), an 'is' file implementing persistence via a Windows Services module, and 'm.l' (main component) — indicating the module naming/format has evolved across samples collected between October 2025 and May 2026.
Microsoft explicitly states it has not observed NeedyMantis itself distributed via a supply-chain compromise, but notes Storm-3069 was originally identified by pivoting off Kaspersky's May 2026 report of a supply-chain compromise of the DAEMON Tools installer (trojanized from 2026-04-08, publicly disclosed and patched 2026-05-06), which Kaspersky found to contain Chinese-language artifacts. Microsoft frames the supply-chain compromise as 'one possible means by which an actor could gain the access necessary to deploy the malware' rather than a confirmed distribution vector for NeedyMantis, so the DAEMON Tools IOCs below are recorded as related pivot-source infrastructure, not confirmed NeedyMantis infrastructure.
MITRE ATT&CK techniques used in TL-2026-2733
Lateral Movement
T1021.002 Remote Services: SMB/Windows Admin Shares; T1570 Lateral Tool Transfer
Defense Evasion
T1027 Obfuscated Files or Information; T1027.007 Obfuscated Files or Information: Dynamic API Resolution; T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1574.001 DLL; T1622 Debugger Evasion
Discovery
T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery
Execution
T1059.001 PowerShell; T1129 Shared Modules; T1569.002 System Services: Service Execution
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer; T1132.001 Data Encoding: Standard Encoding; T1573.001 Encrypted Channel: Symmetric Cryptography
Initial Access
T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
Persistence
T1543.003 Create or Modify System Process: Windows Service; T1574.002 Hijack Execution Flow: DLL Side-Loading
Collection
Affected products and versions in NeedyMantis: Storm-3069 Post-Compromise Modular Malware in
- Poedit — Poedit (WinSparkle update library)
Vulnerable versions: unspecified - abused as a DLL side-loading carrier, not a code vulnerability
Fixed in: N/A - curl project — curl (libcurl.dll)
Vulnerable versions: unspecified - abused as a DLL side-loading carrier
Fixed in: N/A - Vim / TightVNC — Vim, TightVNC (vim64.dll)
Vulnerable versions: unspecified - abused as a DLL side-loading carrier
Fixed in: N/A - Multiple (Microsoft Office, Broadcom, Intel, NVIDIA components) — dbghelp.dll, jli.dll, nvml.dll host applications
Vulnerable versions: unspecified - abused as DLL side-loading carriers
Fixed in: N/A
Remediation for NeedyMantis: Storm-3069 Post-Compromise Modular Malware in
Immediate actions
- Hunt for Microsoft Defender detections TrojanDropper:Win64/NeedyMantis, Behavior:Win64/NeedyMantis, and HackTool:Win32/Impacket across the environment
- Block and alert on network connections to corp.tripswithengine.com and the /library/zip/ URI on port 443
- Inventory installations of Poedit, curl, Vim, and TightVNC for co-located DLLs (WinSparkle.dll, libcurl.dll, vim64.dll, dbghelp.dll, jli.dll, nvml.dll) that do not match expected vendor file hashes
Workarounds
- Where DAEMON Tools is deployed, confirm it is updated to version 12.6.0.2445 or later to remediate the related Kaspersky-reported supply-chain backdoor (patched 2026-05-06)
Longer-term hardening
- Deploy EDR detections for suspicious DLL loading and unexpected DLL files alongside known-good application binaries
- Monitor and restrict hands-on-keyboard use of Impacket-family remote-execution tooling on the network
- Apply application allow-listing and code-signing enforcement to reduce exposure to DLL search-order side-loading
Timeline of NeedyMantis: Storm-3069 Post-Compromise Modular Malware in
- Earliest known NeedyMantis sample: libcurl-themed custom archive (SHA-256 c82520eb...) first seen
- Storm-3069 typosquat domain env-check.daemontools.cc, tied to the DAEMON Tools supply-chain compromise that later led Microsoft to discover NeedyMantis, is registered.
- DAEMON Tools installer trojanization begins (Kaspersky-reported), later cited by Microsoft as the pivot source for identifying Storm-3069 activity
- Distribution window of the trojanized DAEMON Tools Lite installers ends (Kaspersky); fixed release 12.6.0.2445 follows disclosure.
- Kaspersky publicly discloses the DAEMON Tools supply-chain backdoor; vendor ships patched build 12.6.0.2445
- Disc Soft Limited acknowledges the supply-chain compromise of its DAEMON Tools Lite installers.
- First-stage loader (WinSparkle.dll, SHA-256 e842dd76...) first seen
- Custom archive, WinSparkle-themed variant (SHA-256 9cb68f98...) first seen
- Mandiant/Google publish campaign 26-054 describing UNC6863 (suspected China-nexus) deploying SLICKDEMON, BADFALL and QUIC RAT via the DAEMON Tools compromise; a further validation content update follows June 24, 2026.
- Microsoft (MSTIC) publishes NeedyMantis analysis, attributing the activity cluster to Storm-3069
Update history for TL-2026-2733
- 2026-09-29 — NeedyMantis Post-Compromise Malware Provides Persistent Network Access via DLL Side-Loading (Microsoft, Storm-3069): What changed Exploitability NONE → ACTIVE: Microsoft reports NeedyMantis in use in targeted operations since October 2025. Severity and status are unchanged. New MITRE (1) Adds T1574.002 (DLL Side-Loading), the technique the report describe
- 2026-09-28 — NeedyMantis Malware Used by Storm-3069 / UNC6863 to Maintain Long-Term Access in Breached Networks: What changed No field-level escalation. Severity (HIGH), status (ACTIVE) and the record's existing threat_actor (Storm-3069) are unchanged. New indicators (13) 9 new staged DLL paths, the firefox/21.0 hard-coded User-Agent, and the NeedyMan
- 2026-09-28 — NeedyMantis: China-Linked Post-Compromise Malware Framework Enables Covert Persistent Access: What changed No field escalations. The newer report describes the same malware, actor, and C2 as the existing record; its 'exploitability: ACTIVE' classification is not adopted here as it reflects ongoing malware use, not a new exploited-vu
Sources cited for NeedyMantis: Storm-3069 Post-Compromise Modular Malware in
- NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
- Popular DAEMON Tools software compromised
- Kaspersky identifies ongoing supply chain attack on official Daemon Tools website distributing backdoor malware
- DAEMON Tools Supply Chain Attack Compromises Official Installers with Malware
- Attackers compromised Daemon Tools software to deliver backdoors
- Kaspersky uncovers targeted DAEMON Tools supply chain attack affecting manufacturing, government sectors
Detection coverage for TL-2026-2733
As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2733 across Splunk SPL, Microsoft KQL and Sigma, covering 42 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2733
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.