Microsoft has issued a detailed technical analysis warning organizations about a post-compromise malware family dubbed NeedyMantis, which threat actors have deployed to maintain persistent, long-term access inside previously breached enterprise networks. According to the technology giant, the sophisticated malware has been detected in a series of highly targeted intrusions aimed at sensitive sectors, including telecommunications companies, academic institutions, medical nonprofits, intergovernmental bodies, and government contractors. Tracing back activity tied to the tool reveals that its operational deployment dates back to at least October 2025.

The discovery of NeedyMantis by Microsoft security researchers unfolded as they followed up on digital indicators and threat intelligence stemming from an earlier, widely publicized investigation by Kaspersky into a complex supply chain attack targeting DAEMON Tools. In that supply chain compromise, official and cryptographically signed installers for the popular DAEMON Tools Lite disk image utility were found to be harboring malicious code starting April 8, 2026. The software developer subsequently replaced the compromised installer files with clean, secure versions on May 5, 2026.

While Microsoft tracks the broader threat cluster associated with that supply chain operation under the designation Storm-3069 and identifies it as one of the groups utilizing the NeedyMantis framework, the company’s telemetry has not directly linked the initial spread of NeedyMantis itself to the DAEMON Tools supply chain distribution vector. Nevertheless, to aid security teams and defenders in fortifying their perimeters, Microsoft has published comprehensive technical indicators, including specific file hashes, malicious domains, file paths, and advanced threat-hunting queries designed to identify potential compromise across enterprise environments.

How NeedyMantis Runs

In the targeted cases examined by Microsoft analysts, NeedyMantis typically arrives on a compromised host packaged as a distinct bundle consisting of three primary components: a copy of a legitimate, trusted software application; a malicious Dynamic Link Library (DLL) file named identically to a legitimate file loaded by that application; and an encrypted archive bearing the same file name as the malicious DLL. When the legitimate program is executed on the target machine, it inadvertently loads the malicious DLL instead of the expected system file—a stealthy technique widely known in the cybersecurity industry as DLL sideloading.

The legitimate software utilities co-opted by attackers in this manner span a variety of well-known administrative and productivity tools, including the Poedit translation utility, the cURL data transfer tool, the Vim text editor, and the TightVNC remote access application. Furthermore, the malware has been observed masquerading as authentic DLL components originating from major technology developers such as Microsoft Office, Broadcom, Intel, and NVIDIA.

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

In a specific sample subjected to deep analysis by Microsoft, the malicious DLL was engineered to replace WinSparkle.dll, which serves as the automated software update component utilized by the Poedit application. In a typical enterprise intrusion scenario, a human operator who has already managed to establish a foothold inside the internal network utilizes administrative utilities like the Impacket toolkit to copy the malicious bundle across a network share and execute it directly on a targeted workstation or server. The exact mechanisms through which these threat actors achieve their initial network access, however, can vary significantly from one incident to another.

Once successfully loaded into memory through sideloading, the malicious DLL proceeds to unpack the subsequent execution stage from the accompanying encrypted archive. This unpacked stage subsequently decodes the core payload of the malware family. The primary component then initiates outbound communications by establishing a secure connection to a command-and-control server over HTTPS before seamlessly transitioning into a continuous WebSocket connection.

Through this persistent WebSocket channel, human operators maintain the capability to dynamically load and unload supplementary operational modules as well as stream data back and forth. While Microsoft researchers have observed this modular flexibility, the exact functional capabilities of these auxiliary modules remain under investigation and have not been fully detailed. An earlier variant of the malware observed back in October 2025 featured a dedicated persistence module that leveraged standard Windows services to maintain survival across system reboots, though Microsoft’s analysis of the newer variants focused primarily on alternative operational mechanics.

Who Is Behind It

Storm-3069 currently serves as a temporary tracking designation utilized by Microsoft. Under its threat intelligence taxonomy, the company assigns "Storm" identifiers to newly emerging or developing threat clusters until analysts attain a high degree of confidence regarding the true identity, origins, and operational scope of the underlying adversary.

Beyond its observation of Storm-3069’s involvement in campaigns connected to the DAEMON Tools timeline, Microsoft has identified NeedyMantis deployments associated with other activities, suggesting that the malware family may be shared or utilized by multiple distinct threat groups. At present, researchers have not conclusively determined whether all observed instances of NeedyMantis trace back to a single unified actor, nor has Microsoft publicly detailed the specific technical bridges linking Storm-3069 directly to the malware family.

Based on preliminary behavioral assessments, Microsoft evaluates that the activity tied to Storm-3069 originates within China, though the company has refrained from formally attributing the group to a specific state-sponsored nation-state actor at this stage. All NeedyMantis activity documented by Microsoft thus far exhibits characteristics closely aligned with operations typically attributed to China-nexus threat groups, such as targeting profiles that mirror strategic Chinese interests and an operational preference for surgical, low-volume strikes against a highly restricted number of carefully selected organizations.

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

When security firm Kaspersky initially disclosed the DAEMON Tools supply chain compromise in May, analysts identified Chinese-language artifacts embedded within the malicious code, though they similarly stopped short of assigning formal attribution to a specific threat group. Meanwhile, the Google Threat Intelligence Group tracks the specific adversary behind the DAEMON Tools supply chain campaign under the moniker UNC6863. In June, Mandiant characterized UNC6863 as a suspected China-nexus actor that leveraged the compromised software distribution mechanism to deploy advanced malware. It remains undetermined whether UNC6863 and Microsoft’s Storm-3069 represent the same overarching threat group or allied entities.

How to Check for NeedyMantis

To assist enterprise security teams in detecting potential dwell time or active compromises, Microsoft has released extensive technical guidance and indicators of compromise. Microsoft Defender Antivirus recognizes the threat components and flags them under distinct signatures, specifically identifying them as TrojanDropper:Win64/NeedyMantis and Behavior:Win64/NeedyMantis. Additionally, the company has provided specialized hunting queries configured to search for malicious file paths within Defender XDR, alongside queries designed to identify command-and-control domains and associated user agents across both Defender XDR and Microsoft Sentinel platforms.

Security administrators reviewing these guidelines should note that standard hunting queries typically default to a seven-day lookback window. Because the primary file artifacts analyzed by researchers date back to October 2025 and May 2026, running the queries in their default state without adjusting the time parameters will not surface historical events from those periods. Furthermore, security personnel are cautioned that discovering a file path matching Poedit does not inherently confirm an active compromise, as WinSparkle.dll is an authentic and legitimate dependency of the Poedit application. Defenders must carefully verify the cryptographic hashes of any identified files against the officially published indicators.

To harden networks against these tactics, Microsoft strongly recommends implementing a robust security posture across its ecosystem. Key defensive measures include enabling cloud-delivered protection, activating "block at first sight" capabilities, running Endpoint Detection and Response in block mode, enforcing network protection, utilizing automatic attack disruption features, and deploying targeted attack surface reduction rules. Organizations are also advised to monitor outbound network telemetry closely for any unauthorized communication attempts directed toward known command-and-control infrastructure—an administrative control that operates independently of endpoint security agents.

While Microsoft’s current findings indicate that NeedyMantis was not delivered directly through the tampered software installers associated with the DAEMON Tools incident, developers of the affected software have maintained their previous advisory. Any user who downloaded or installed the free version of DAEMON Tools Lite 12.5.1 during the vulnerable operational window is strongly urged to completely uninstall the software, perform a comprehensive system scan to ensure integrity, and upgrade immediately to version 12.6 sourced exclusively from the official vendor website.

Leave a Reply

Your email address will not be published. Required fields are marked *