IOC Radar

Indicators are what attackers leave behind. Stolen credentials are what they arrive with.

Check Your Exposure
TLP:WHITE4 IOCs

NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

MT
Microsoft Threat Intelligence
Published September 28, 2026Original Report

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTUREcorp.tripswithengine.…CAPABILITYCobalt StrikeImpacketVICTIMunknown
Adversary
Infrastructure(1)
Capability(2)
Victim

Indicators of Compromise

Indicators of Compromise4

TypeIndicatorConfidenceScoreFirst Seen
Domaincorp.tripswithengine.com
intel-blogmalwarenetwork
High
63
Sep 29, 26
SHA256e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e
file-hashintel-blogloader
Medium
53
Sep 29, 26
SHA256c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77
file-hashintel-blogmalware
Medium
53
Sep 29, 26
SHA2569cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef
file-hashintel-blogloader
Medium
53
Sep 29, 26

IOC Relationship Graph

IOC Relationship Graph4 total IOCs
DomainSHA256
SHA2563Domain1Malware2REPORTNeedyMantis: Unpacking a pCobalt StrikeImpacket
scroll to zoom · drag to pan · click IOC to open