Microsoft has identified a malware strain named NeedyMantis that hackers use to ensure prolonged access to compromised networks. This discovery was made during an analysis of cyber threats affecting various sectors such as telecommunications, academia, and government contractors. The presence of NeedyMantis has been traced back to at least October 2025, indicating its persistent threat in the cybersecurity landscape.
Details of the NeedyMantis Malware
NeedyMantis was uncovered while Microsoft was investigating indicators from Kaspersky’s research on a supply chain attack involving DAEMON Tools. In this attack, malicious code was embedded into DAEMON Tools Lite installers, which were publicly available from April 8, 2026, until clean versions replaced them on May 5. Activity associated with this attack is tracked by Microsoft under the identifier Storm-3069, a group believed to be utilizing NeedyMantis. However, the spread of the malware through a supply chain attack has not been directly observed.
The malware comprises three components: a legitimate application, a malicious DLL masquerading as a legitimate file, and an encrypted archive sharing the DLL’s name. Once the application runs, the DLL is loaded, employing a technique known as DLL sideloading. Common legitimate applications used include Poedit, curl, and TightVNC. Notably, in Microsoft’s detailed analysis, the malware replaced the WinSparkle.dll file used by Poedit.
Operational Tactics and Impact
Upon execution, the malicious DLL extracts and initiates the malware’s main component from the encrypted archive. This component establishes communication with a command-and-control server over HTTPS, transitioning to a WebSocket connection to facilitate additional module loading. The further functions of these modules remain unconfirmed. An older version of NeedyMantis included a persistence module for Windows services, but details on how the newer version maintains its presence are not provided.
Microsoft has attributed Storm-3069’s operations to originate from China, though no direct links to specific state actors have been established. The malware’s deployment aligns with Chinese interests, as observed in the targeted organizations. Furthermore, the Google Threat Intelligence Group and Mandiant have linked the DAEMON Tools campaign to another entity, UNC6863, suspected to have connections to China.
Detection and Defense Strategies
To counter NeedyMantis, Microsoft has released several indicators of compromise, including SHA-256 hashes and file paths for malicious DLLs. They recommend using Microsoft Defender Antivirus, which recognizes the threat as TrojanDropper:Win64/NeedyMantis. Security settings such as cloud-delivered protection and network protection are advised to mitigate risks.
Additionally, Microsoft suggests vigilance in monitoring outbound network traffic for connections to the command-and-control domain. Users of the affected DAEMON Tools Lite version are advised to uninstall it, conduct a full system scan, and update to the latest version to safeguard against potential threats.
As cybersecurity threats evolve, staying informed and adopting recommended defense measures is crucial in protecting networks against sophisticated malware like NeedyMantis.
