{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/actors/storm-3069/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["Storm-3069"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["persistence","defense-evasion","post-compromise","modular-malware","storm-3069"],"_cs_type":"threat","_cs_vendors":[],"content_html":"\u003cp\u003eNeedyMantis is a modular post-compromise malware framework identified by Microsoft Threat Intelligence, primarily used to maintain long-term access in victim environments. First observed in October 2025, the malware is typically deployed in the post-compromise stage of an intrusion, meaning the initial access vector is variable and independent of the NeedyMantis framework itself. Targeted sectors include telecommunications, universities, medical nonprofits, and government contractors.\u003c/p\u003e\n\u003cp\u003eThe framework is highly modular, employing a first-stage loader and encrypted file archives, often packaged alongside legitimate software. It leverages DLL sideloading to execute by masquerading as components from software like Poedit, curl, and Vim, or by spoofing system DLLs associated with Microsoft, Broadcom, Intel, and NVIDIA. NeedyMantis utilizes x64 shellcode, dynamic API resolution, and obfuscated stack strings to evade detection. The framework's design supports the deployment of additional modules to extend capabilities, making it a persistent and adaptable tool for targeted operations linked to threat actors operating from China.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes initial access via an undisclosed vector (e.g., supply chain compromise).\u003c/li\u003e\n\u003cli\u003eAttacker uses post-exploitation tools (e.g., Impacket) to copy legitimate software, a malicious DLL loader, and a custom file archive to the target device.\u003c/li\u003e\n\u003cli\u003eAttacker triggers the execution of the legitimate software, which leads to the sideloading of the malicious DLL (e.g., WinSparkle.dll).\u003c/li\u003e\n\u003cli\u003eThe first-stage loader resolves Windows APIs dynamically and deobfuscates stack strings.\u003c/li\u003e\n\u003cli\u003eThe loader decrypts and extracts the second-stage component from the accompanying file archive.\u003c/li\u003e\n\u003cli\u003eThe second-stage loader initializes the modular framework.\u003c/li\u003e\n\u003cli\u003eThe framework connects to C2 infrastructure to receive commands or additional malicious modules.\u003c/li\u003e\n\u003cli\u003eAttacker performs follow-on operations such as lateral movement or exfiltration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful deployment of NeedyMantis provides an attacker with persistent, long-term access to sensitive environments. Observed victims include critical infrastructure providers, governmental organizations, and educational institutions. The framework's modularity enables attackers to tailor their activities for espionage or further malicious operations, potentially resulting in data exfiltration or the compromise of additional systems within the targeted network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eBlock and hunt for the file hashes of observed NeedyMantis loaders and archives in the IOC list.\u003c/li\u003e\n\u003cli\u003eImplement detection rules for DLL sideloading behavior involving the specified DLL names (e.g., WinSparkle.dll, libcurl.dll, vim64.dll) when executed from non-standard application paths.\u003c/li\u003e\n\u003cli\u003eMonitor for the creation of files matching the known malicious DLL and archive naming patterns (e.g., %ProgramData%\\office\\dbghelp.dll) on enterprise endpoints.\u003c/li\u003e\n\u003cli\u003eUse EDR telemetry to audit process creation events where legitimate software (e.g., Poedit, Vim, curl) spawns suspicious child processes or loads unexpected DLLs from the application directory.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-28T16:17:15Z","date_published":"2026-09-28T16:17:15Z","id":"https://feed.craftedsignal.io/briefs/2026-09-needymantis/","summary":"NeedyMantis is a modular, multi-stage malware framework used by threat actors like Storm-3069 to establish persistence and perform follow-on operations via DLL sideloading and custom encrypted archives.","title":"NeedyMantis Modular Post-Compromise Framework","url":"https://feed.craftedsignal.io/briefs/2026-09-needymantis/"}],"language":"en","title":"CraftedSignal Threat Feed - Storm-3069","version":"https://jsonfeed.org/version/1.1"}