Date: 09/29/2026
Severity: High
Summary
NeedyMantis is a modular post-compromise malware family used in targeted intrusions against telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Active since at least October 2025, it is typically deployed after initial access to maintain long-term persistence and support follow-on operations. Microsoft has linked observed activity to Storm-3069, associated with the DAEMON Tools supply chain compromise, with activity aligning with China-based threat actors, although attribution remains uncertain. Its multi-stage loaders, encrypted archives, custom file format, modular architecture, and C2 capabilities help operators evade analysis and maintain persistent access.
Indicators of Compromise (IOC) List
Domains/URLs | corp.tripswithengine.com |
Hash | e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e
9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef
c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "corp.tripswithengine.com" or url like "corp.tripswithengine.com" or siteurl like "corp.tripswithengine.com" |
Detection Query 2 : | sha256hash IN ("e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e","c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77","9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef")
|
Reference:
https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/#indicators-of-compromise