Particle.news

Microsoft Details NeedyMantis Malware Used to Maintain Long-Term Network Access

The company published technical indicators and Defender guidance to help defenders find, block and remediate infections.

Overview

  • Microsoft published a detailed technical analysis and indicators of compromise on Sept. 28–29, 2026, including SHA-256 hashes, a C2 domain, a hard-coded user agent, Defender detection names and hunting queries.
  • The company found NeedyMantis while following up on Kaspersky’s April–May 2026 DAEMON Tools supply-chain investigation but has not seen the malware distributed through the tampered installers.
  • In observed cases the malware arrives as a three-part bundle — a legitimate program, a malicious DLL named for a legitimate file, and an encrypted archive — and uses DLL sideloading to run a loader on already-compromised machines.
  • NeedyMantis’ main component connects over HTTPS then upgrades to a WebSocket command-and-control channel that can load and unload modular payloads though the specific functions of those modules remain unconfirmed.
  • Microsoft links the activity to a cluster it calls Storm-3069 and notes China-origin tradecraft patterns while other vendors track related activity as UNC6863; the company cautions that actor ties and current active use remain uncertain and urges defenders to apply the published EDR and network mitigations.