Canadian Cyber Security Journal
SOCIAL:
Filed under: Trends

Microsoft Dissects NeedyMantis, a Quiet Backdoor Aimed at Telecoms and Government Contractors

What Happened

Microsoft published its analysis of NeedyMantis, a modular backdoor built to hold long-term access inside breached networks. Microsoft tracks the operator as Storm-3069 and assesses the activity as China-origin, though it has not tied the group to a confirmed nation-state actor. Google Threat Intelligence follows a related actor as UNC6863. Victims since October 2025 include telecommunications firms, universities, medical nonprofits, intergovernmental organizations, and government contractors. The malware sideloads DLLs through legitimate programs such as Poedit, curl, Vim, and TightVNC. It loads modules in stages and talks to its server over HTTPS and WebSocket. Investigators found it while examining the tampered DAEMON Tools installers distributed over a four-week window starting April 8, 2026, but Microsoft has not seen the malware spread through the supply chain attack. Details are at The Hacker News and SecurityWeek.

Why This Matters for Canadian Organizations

The victim list reads like a Canadian critical infrastructure register. Telecommunications carriers sit at the center of Bill C-26 designation debates, and Canadian universities and research institutes hold data foreign intelligence services want. Government contractors link private networks to federal projects. An actor who values quiet persistence over quick payouts is hard to catch with standard alerts. The malware also abuses trusted software, so file-name allowlists will not help you.

What to Do

Search your environment for the indicators Microsoft published, including outbound traffic on port 443 to corp.tripswithengine[.]com and unexpected copies of WinSparkle.dll under the Poedit directory. Check whether any endpoint installed DAEMON Tools during the four-week window. Turn on cloud-delivered protection, block at first sight, EDR in block mode, and network protection in Microsoft Defender. Review DLL sideloading behaviour from signed utilities. Report confirmed findings to the Canadian Centre for Cyber Security.

Follow more threat activity in our Trends section and the daily News brief.

Enjoy this article? Don’t forget to share.