# NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operations

> Microsoft (MSTIC) details NeedyMantis, a modular post-compromise malware family attributed to activity cluster Storm-3069, deployed via DLL sideloading of legitimate software (Poedit, curl, Vim, TightVNC) after initial access is already established. The malware uses a multi-stage loader chain, a custom encrypted archive format, and WebSocket-based C2 with RC4-encrypted, RtlCompressBuffer-compressed traffic, and has been observed against telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors since at least October 2025.

- **Published:** 2026-09-28T00:00:00Z
- **Last reviewed:** 2026-09-29T13:37:12.264Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2733
- **ID:** TL-2026-2733
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Storm-3069 (China)
- **Detections:** 9 · **IOCs:** 42 (full data via the Threadlinqs MCP server — Purple tier)

## Description

NeedyMantis is a modular post-compromise malware family that Microsoft Threat Intelligence attributes to an activity cluster it tracks as Storm-3069. Microsoft states the activity 'aligns with threat actors operating from China' but explicitly has 'not attributed Storm-3069 to a Chinese nation-state actor.' Deployment is strictly post-compromise: in observed intrusions, operators already possessing environment access used the Impacket toolkit during hands-on-keyboard activity to copy a legitimate application, a malicious DLL, and a custom encrypted file archive onto the target host, triggering DLL side-loading. Observed carrier applications include Poedit (WinSparkle.dll), curl (libcurl.dll), Vim and TightVNC (vim64.dll), and components branded to resemble Microsoft Office, Broadcom, Intel, and NVIDIA software (dbghelp.dll, jli.dll, nvml.dll).

The infection chain runs in three stages. The first-stage loader DLL uses obfuscated stack strings and mathematically-obfuscated constants to hide Windows API/DLL references, checks ProcessDebugFlags and ThreadHideFromDebugger to detect debuggers, and extracts a second-stage loader from the accompanying custom file archive. The second-stage loader carries a .ps1 extension but is actually x64 shellcode: it decodes and decompresses an embedded binary using a configurable ROR (rotate-right) algorithm and resolves Windows APIs via hash values rather than plaintext imports, ultimately executing a minimized custom PE format. The third stage is the main component, which creates a mutex of the form '<username>-<process name>' (e.g., 'Contoso-Poedit.exe'), loads a configuration module masquerading as dnsapi.dll (a 3448-byte structure holding the C2 host, port 443, URI /library/zip/, a 300-second sleep timer, and proxy-credential fields), and a communications module masquerading as ws2_32.dll that establishes and maintains a WebSocket session (two implementation variants exist: WinINet-based and Libwebsockets-based) using the hard-coded user-agent 'firefox/21.0'.

Initial contact is an HTTPS GET whose response Set-Cookie header carries a Base64-encoded, RtlDecompressBuffer-decompressed JSON blob of host reconnaissance data (computer name, username, process name, parent process, file listing, process list) before the session upgrades to WebSocket. Post-upgrade traffic uses a 44-byte binary frame header (16-byte XOR key, uncompressed/compressed length fields, a command number, and a data-length field) with RtlCompressBuffer compression and optional RC4 encryption. Key exchange has the implant generate a 1024-byte random buffer, take its first 32 bytes as an RC4 key, and send a 256-byte RC4-encrypted buffer beginning with the string 'google.com' plus random padding (length randomized 292-1282 bytes) so the C2 server can rederive and validate the key before acknowledging with a random command number. The command set includes outbound codes 1110 (send computer/username), 1112 (send a hard-coded identifier), and 1150 (keep-alive), and inbound codes 1020/1030 (load/unload module), 1050/1150 (dispatch data to a loaded module), and 1070 (clear active flags) — implementing NeedyMantis's plugin-style extensibility.

The custom file archive format itself is XOR-encoded at the outer layer and RtlDecompressBuffer-decompressed, with individual entries XOR-decoded by filename and separately decompressed. One recovered WinSparkle-themed archive bundled legitimate 7-Zip and Sysinternals components alongside the malicious dnsapi.dll (config), ws2_32.dll (comms), and msvcrt140.dll (shellcode loader) modules; a second, libcurl-themed archive variant instead bundled 300.c (config), 300.s (comms), an 'is' file implementing persistence via a Windows Services module, and 'm.l' (main component) — indicating the module naming/format has evolved across samples collected between October 2025 and May 2026.

Microsoft explicitly states it has not observed NeedyMantis itself distributed via a supply-chain compromise, but notes Storm-3069 was originally identified by pivoting off Kaspersky's May 2026 report of a supply-chain compromise of the DAEMON Tools installer (trojanized from 2026-04-08, publicly disclosed and patched 2026-05-06), which Kaspersky found to contain Chinese-language artifacts. Microsoft frames the supply-chain compromise as 'one possible means by which an actor could gain the access necessary to deploy the malware' rather than a confirmed distribution vector for NeedyMantis, so the DAEMON Tools IOCs below are recorded as related pivot-source infrastructure, not confirmed NeedyMantis infrastructure.

## MITRE ATT&CK

- T1574.001 DLL
- T1036.005 Match Legitimate Resource Name or Location
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1622 Debugger Evasion
- T1071.001 Application Layer Protocol: Web Protocols
- T1573.001 Encrypted Channel: Symmetric Cryptography
- T1132.001 Data Encoding: Standard Encoding
- T1560.003 Archive Collected Data: Archive via Custom Method
- T1129 Shared Modules
- T1569.002 System Services: Service Execution
- T1570 Lateral Tool Transfer
- T1082 System Information Discovery
- T1057 Process Discovery
- T1059.001 PowerShell
- T1021.002 Remote Services: SMB/Windows Admin Shares
- T1105 Ingress Tool Transfer
- T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
- T1543.003 Create or Modify System Process: Windows Service
- T1027.013 Obfuscated Files or Information: Encrypted/Encoded File
- T1027.007 Obfuscated Files or Information: Dynamic API Resolution
- T1033 System Owner/User Discovery
- T1083 File and Directory Discovery
- T1574.002 Hijack Execution Flow: DLL Side-Loading

## Sources

- [NeedyMantis: Unpacking a post-compromise malware family used in targeted operations](https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/)
- [Popular DAEMON Tools software compromised](https://securelist.com/tr/daemon-tools-backdoor/119654/)
- [Kaspersky identifies ongoing supply chain attack on official Daemon Tools website distributing backdoor malware](https://www.kaspersky.com/about/press-releases/kaspersky-identifies-ongoing-supply-chain-attack-on-official-daemon-tools-website-distributing-backdoor-malware)
- [DAEMON Tools Supply Chain Attack Compromises Official Installers with Malware](https://thehackernews.com/2026/05/daemon-tools-supply-chain-attack.html)
- [Attackers compromised Daemon Tools software to deliver backdoors](https://www.helpnetsecurity.com/2026/05/06/daemon-tools-compromised-backdoors-supply-chain-attack/)
- [Kaspersky uncovers targeted DAEMON Tools supply chain attack affecting manufacturing, government sectors](https://industrialcyber.co/supply-chain-security/kaspersky-uncovers-targeted-daemon-tools-supply-chain-attack-affecting-manufacturing-government-sectors/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2733
