<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Storm-3069 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/actors/storm-3069/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 16:17:15 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/actors/storm-3069/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>NeedyMantis Modular Post-Compromise Framework</title><link>https://feed.craftedsignal.io/briefs/2026-09-needymantis/</link><pubDate>Mon, 28 Sep 2026 16:17:15 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-needymantis/</guid><description>NeedyMantis is a modular, multi-stage malware framework used by threat actors like Storm-3069 to establish persistence and perform follow-on operations via DLL sideloading and custom encrypted archives.</description><content:encoded><![CDATA[<p>NeedyMantis is a modular post-compromise malware framework identified by Microsoft Threat Intelligence, primarily used to maintain long-term access in victim environments. First observed in October 2025, the malware is typically deployed in the post-compromise stage of an intrusion, meaning the initial access vector is variable and independent of the NeedyMantis framework itself. Targeted sectors include telecommunications, universities, medical nonprofits, and government contractors.</p>
<p>The framework is highly modular, employing a first-stage loader and encrypted file archives, often packaged alongside legitimate software. It leverages DLL sideloading to execute by masquerading as components from software like Poedit, curl, and Vim, or by spoofing system DLLs associated with Microsoft, Broadcom, Intel, and NVIDIA. NeedyMantis utilizes x64 shellcode, dynamic API resolution, and obfuscated stack strings to evade detection. The framework's design supports the deployment of additional modules to extend capabilities, making it a persistent and adaptable tool for targeted operations linked to threat actors operating from China.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker establishes initial access via an undisclosed vector (e.g., supply chain compromise).</li>
<li>Attacker uses post-exploitation tools (e.g., Impacket) to copy legitimate software, a malicious DLL loader, and a custom file archive to the target device.</li>
<li>Attacker triggers the execution of the legitimate software, which leads to the sideloading of the malicious DLL (e.g., WinSparkle.dll).</li>
<li>The first-stage loader resolves Windows APIs dynamically and deobfuscates stack strings.</li>
<li>The loader decrypts and extracts the second-stage component from the accompanying file archive.</li>
<li>The second-stage loader initializes the modular framework.</li>
<li>The framework connects to C2 infrastructure to receive commands or additional malicious modules.</li>
<li>Attacker performs follow-on operations such as lateral movement or exfiltration.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful deployment of NeedyMantis provides an attacker with persistent, long-term access to sensitive environments. Observed victims include critical infrastructure providers, governmental organizations, and educational institutions. The framework's modularity enables attackers to tailor their activities for espionage or further malicious operations, potentially resulting in data exfiltration or the compromise of additional systems within the targeted network.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Block and hunt for the file hashes of observed NeedyMantis loaders and archives in the IOC list.</li>
<li>Implement detection rules for DLL sideloading behavior involving the specified DLL names (e.g., WinSparkle.dll, libcurl.dll, vim64.dll) when executed from non-standard application paths.</li>
<li>Monitor for the creation of files matching the known malicious DLL and archive naming patterns (e.g., %ProgramData%\office\dbghelp.dll) on enterprise endpoints.</li>
<li>Use EDR telemetry to audit process creation events where legitimate software (e.g., Poedit, Vim, curl) spawns suspicious child processes or loads unexpected DLLs from the application directory.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>persistence</category><category>defense-evasion</category><category>post-compromise</category><category>modular-malware</category><category>storm-3069</category></item></channel></rss>