NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

    Date: 09/29/2026

    Severity: High

    Summary

    NeedyMantis is a modular post-compromise malware family used in targeted intrusions against telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Active since at least October 2025, it is typically deployed after initial access to maintain long-term persistence and support follow-on operations. Microsoft has linked observed activity to Storm-3069, associated with the DAEMON Tools supply chain compromise, with activity aligning with China-based threat actors, although attribution remains uncertain. Its multi-stage loaders, encrypted archives, custom file format, modular architecture, and C2 capabilities help operators evade analysis and maintain persistent access. 

    Indicators of Compromise (IOC) List

    Domains/URLs

    corp.tripswithengine.com

    Hash

    e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e

    9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef

    c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "corp.tripswithengine.com" or url like "corp.tripswithengine.com" or siteurl like "corp.tripswithengine.com"

    Detection Query 2 :

    sha256hash IN ("e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e","c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77","9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef")

    Reference: 

    https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/#indicators-of-compromise


    Tags

    MalwareThreat ActorCommunicationsEducationHealthcare and Public HealthGovernment Services and FacilitiesSupply chain attackChina

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags