Overview
- Microsoft published a detailed technical analysis and indicators of compromise on Sept. 28–29, 2026, including SHA-256 hashes, a C2 domain, a hard-coded user agent, Defender detection names and hunting queries.
- The company found NeedyMantis while following up on Kaspersky’s April–May 2026 DAEMON Tools supply-chain investigation but has not seen the malware distributed through the tampered installers.
- In observed cases the malware arrives as a three-part bundle — a legitimate program, a malicious DLL named for a legitimate file, and an encrypted archive — and uses DLL sideloading to run a loader on already-compromised machines.
- NeedyMantis’ main component connects over HTTPS then upgrades to a WebSocket command-and-control channel that can load and unload modular payloads though the specific functions of those modules remain unconfirmed.
- Microsoft links the activity to a cluster it calls Storm-3069 and notes China-origin tradecraft patterns while other vendors track related activity as UNC6863; the company cautions that actor ties and current active use remain uncertain and urges defenders to apply the published EDR and network mitigations.