28-09-2026
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/
Report completeness: High
Actors/Campaigns:
Storm-3069
Threats:
Needymantis
Supply_chain_technique
Dll_sideloading_technique
Impacket_tool
Tightvnc_tool
Victims:
Telecommunications, Universities, Medical nonprofits, Intergovernmental organizations, Government contractors
Industry:
Education, Healthcare, Government, Telco
Geo:
China, Chinese
TTPs:
Tactics: 3
Technics: 0
ChatGPT TTPs:
do not use without manual checkT1027, T1027.007, T1027.013, T1036.005, T1036.008, T1071.001, T1129, T1140, T1543.003, T1573.001, have more...
IOCs:
File: 16
Hash: 3
Domain: 1
Soft:
Microsoft Defender, Microsoft Defender for Endpoint, curl, TightVNC, Microsoft Office, Sysinternals
Algorithms:
zip, rc4, sha1, xor, sha256, base64, md5
Functions:
Set-Cookie
Win API:
RtlDecompressBuffer, decompress, RtlDecompressBuffer decompress, WinHttpOpen, RtlCompressBuffer
Languages:
powershell, python
Platforms:
intel, x86, x64