Microsoft recently disclosed NeedyMantis, a previously unidentified malware framework deployed by a China-based threat actor against telecommunications companies, universities, medical organizations, and government agencies. The framework provided long-term access to compromised networks — exactly the kind of sophisticated, persistent threat that keeps CISOs awake at night.
But here’s what the security industry doesn’t talk about enough: even advanced persistent threat frameworks have to obey the rules of the operating system. They need to write files to disk. They need to move laterally across networks by writing to remote shares. They need to establish persistence through executables, scripts, or DLLs stored somewhere on the file system.
FileSure Defend enforces file access policies at the kernel level — before the file system processes the operation. It doesn’t matter how sophisticated the malware is, what obfuscation techniques it uses, or whether it’s a zero-day. If the delivery mechanism can’t write the payload to disk, the attack stops before it starts.
Blocking Initial Payload Delivery
APT malware typically arrives through phishing emails or compromised websites. The email client or browser process attempts to write the executable payload to disk — maybe a .exe, maybe a .dll, maybe a PowerShell script.
FileSure’s program name filters block this at the file system operation layer:
File name filter: *.exe;*.dll;*.bat;*.cmd;*.ps1;*.vbs
Program name filter: \outlook.exe;\chrome.exe;\firefox.exe;\msedge.exe
Operations: Write, Create
Drive type: Hard drives, Workstations
Email clients and browsers simply cannot write executable or script files to local drives. The payload delivery fails. No execution, no persistence, no lateral movement — because the malware never lands.
No signature database. No behavioral analysis of what the malware does after it runs. Just a simple rule: these programs don’t write these file types, ever.
Killing Lateral Movement at the File System
Once malware compromises one workstation, it typically attempts to spread across the network by writing files to remote shares via SMB. A compromised machine tries to drop executables on file servers or other workstations to establish a foothold.
FileSure’s REMOTE ACCESS filter blocks this on the target system:
File name filter: *.exe;*.dll;*.bat;*.cmd;*.ps1
Program name filter: REMOTE ACCESS (exact, case sensitive)
Operations: Write, Create
Drive type: Hard drives
Install type: Servers
No remote machine can write executable files to the server’s local drives through network share access. Local processes on the server operate without restriction. The attacker’s lateral movement attempt dies at the file system layer on the target — even if the source workstation is fully compromised.
The Upstream Intervention Advantage
Most security tools try to detect malware after it’s already running — analyzing behavior, checking signatures, monitoring process injection. That’s downstream mitigation. You’re already compromised; you’re just trying to limit the damage.
FileSure operates upstream. The malware payload never lands on disk. The lateral movement file write fails. The attack stops at the delivery stage, not the damage control stage.
For organizations managing compliance requirements under HIPAA, FISMA, or CJIS — where audit trails and access controls for sensitive data are mandatory — this approach provides a durable enforcement layer that doesn’t depend on keeping signature databases current or analyzing every new malware variant.
NeedyMantis may be sophisticated. But it still needs to write files to disk. And that’s where it would have failed.
Start a free trial at bystorm.com and see how kernel-level file system enforcement stops attacks that signature-based tools miss.
Source: ‘NeedyMantis’ Provides Long-Term Access to Compromised Networks
Category: Threat Intelligence
Tags: needymantis, apt, lateral movement, kernel filter driver, file system security, smb blocking, payload delivery prevention