Antivirus
Sep 29, 2026
Severity: HIGH · Priority: P2 — targeted espionage-oriented backdoor found in high-value sector networks, escalate on hit
These signatures detect components of NeedyMantis, a modular post-compromise backdoor framework documented by Microsoft Threat Intelligence on September 28, 2026, and attributed with confidence to China-based operators tracked as Storm-3069. NeedyMantis has been found in a small number of highly targeted intrusions — telecommunications providers, universities, medical nonprofits, intergovernmental organisations, and government contractors — and the confirmed activity spans from October 2025 to May 2026, indicating operators have used it for extended covert access rather than short-term or opportunistic intrusions. Microsoft discovered the framework while following indicators from the DAEMON Tools supply-chain compromise, though NeedyMantis itself was not delivered through the trojanised installers; it is typically deployed after an attacker has already established initial access by some other means.
The framework's design prioritises evasion and persistence. Its components are loaded through DLL side-loading to blend into legitimate software processes, and its payload is stored in a custom encrypted archive format with varying filenames, XOR keys, compression settings, and offsets between samples — making static detection significantly harder. The two-stage loading chain uses a first-stage loader that unpacks a second stage (a PowerShell file that despite its extension contains x64 shellcode), which in turn decodes and decompresses the main NeedyMantis component. The framework communicates with its C2 server over HTTPS with a WebSocket upgrade, using a hardcoded User-Agent string (firefox/21.0) in its communications DLL — an identifying detail with very low false-positive risk, since no legitimate modern software sends this browser version. The framework is modular; operators can extend it by loading additional plugins. The three detected files are two of the malware's encrypted archive packages and the DLL loader component.
If GajAV flags one of these files, treat it as confirmation of a targeted intrusion at an advanced stage — the malware is deployed post-access, meaning an attacker has already breached the system by other means. The immediate priority is understanding the entry point (starting from the DAEMON Tools supply-chain exposure window — April 8 through the cleaned release — for machines that ran versions 12.5.0.2421 to 12.5.0.2434) and the scope of access the NeedyMantis framework has maintained. Conduct a full incident-response investigation rather than single-machine remediation: because NeedyMantis is designed for long-term access and espionage, lateral movement and additional persistence mechanisms are likely. Look for unexpected DLLs in software installation directories, particularly files named WinSparkle.dll, libcurl.dll, or dnsapi.dll that differ from vendor-shipped versions, and for outbound HTTPS connections to corp.tripswithengine[.]com with the firefox/21.0 User-Agent. Machines that ran the affected DAEMON Tools versions should be upgraded to 12.6.0.2445 or later and reviewed for any NeedyMantis staging.
Read the full update