News / Cybersecurity
NeedyMantis: A Modular Post-Compromise Malware Targeting Strategic Organizations Published on 28 September 2026 by Christ-loisele (3 min read)
Microsoft Threat Intelligence reveals NeedyMantis, a malicious framework deployed after an initial intrusion to maintain persistent access. This malware, linked to the actor Storm-3069 and the compromise of DAEMON Tools, targets telecommunications, universities, and government institutions.
Video: NeedyMantis: Storm-3069's DLL Side-Load Backdoor (Threadlinqs, YouTube)
A Post-Compromise Malware with Advanced Techniques
NeedyMantis is a modular malware designed to activate after an attacker has already penetrated a target network, according to Microsoft Threat Intelligence. Unlike supply chain attacks such as the DAEMON Tools compromise (discovered by Microsoft and UNDERCODE NEWS ), NeedyMantis is not delivered via this vector. Instead, it exploits existing vulnerabilities to deploy, particularly through DLL sideloading techniques abusing legitimate software such as Poedit, curl, Vim, or TightVNC.
The malware uses custom encrypted archives, obfuscated executable formats, and dynamic modules to evade detection. It communicates with a command and control (C2 ) server via the domain corp.tripswithengine[.]com (port 443), employing WebSocket and binary protocols to remain undetected. Microsoft highlights that NeedyMantis combines modern techniques: stacked strings, dynamically resolved Windows functions, and anti-debugging checks, making its analysis complex.
NeedyMantis is typically deployed after a threat actor has already established access within the target environment, turning an initial intrusion into a persistent backdoor.
Illustration: Lawing Tech
Storm-3069 and the Chinese Origin of the Attacks
Microsoft associates NeedyMantis with the threat actor Storm-3069 , whose activities date back to at least October 2025. While the operations are geolocated in China, Microsoft specifies that it has not attributed Storm-3069 to a Chinese state group , according to analyses published on the Microsoft Security Blog and confirmed by Windows Forum . Targets include sensitive sectors: telecommunications, universities, nonprofit medical organizations, intergovernmental entities, and government contractors.
A documented incident shows the use of the tool Impacket to copy and execute malicious components from a network share, illustrating manual intrusion. Kaspersky had previously warned about malicious binaries in the official installers of DAEMON Tools Lite , distributed starting in April 2026 (source ).
What This Changes Here
For businesses and government agencies in Benin and West Africa, the discovery of NeedyMantis highlights the importance of strengthening post-intrusion controls. Organizations in the telecommunications, education, or healthcare sectors, often targeted by actors like Storm-3069, could see their systems compromised by modular malware deployed after an initial breach. Detecting DLL sideloading techniques, particularly through tools like Microsoft Defender for Endpoint, would become critical to limiting the damage.
Public administrations and government contractors, frequently targeted, should also audit their network shares and monitor connections to suspicious domains like corp.tripswithengine[.]com. The use of legitimate tools (Poedit, Vim) as malware vectors underscores the need to update third-party software and apply least-privilege principles to limit the impact of an initial compromise.
Microsoft’s technical recommendations
Microsoft advises organizations to block connections to corp.tripswithengine[.]com and look for traces of Impacket execution or suspicious DLL sideloading. Companies using solutions like Defender XDR or Microsoft Sentinel can apply the hashes and search queries provided by Microsoft to detect NeedyMantis. A thorough investigation should cover credential theft, lateral movement, persistence mechanisms, and staging servers, as Microsoft outlines in its analyses (source ).
Sources