Microsoft has released an in-depth examination of a sophisticated malware framework known as NeedyMantis, attributed to a China-based cyber group. This framework has been implicated in attacks targeting telecommunications and government entities.
Discovery and Impact of NeedyMantis
The NeedyMantis framework came to light during the investigation of indicators of compromise linked to the May 2026 Daemon Tools supply chain attack. This incident led to the infection of thousands of systems via compromised Daemon Tools software distributed through the official website, with a backdoor installed on a select few. Targets included government, scientific, manufacturing, and retail sectors in Belarus, Russia, and Thailand.
Microsoft’s recent report provides an exhaustive breakdown of NeedyMantis, which is a modular post-compromise malware used by the Daemon Tools hackers for pinpointed assaults on universities, government contractors, telecom companies, as well as medical and intergovernmental organizations.
Technical Details and Deployment
NeedyMantis has been operational since at least October 2025, likely involving multiple China-based threat actors. The group responsible for the Daemon Tools attack, identified as Storm-3069, has not been officially linked to any Chinese state-sponsored entities. The malware is designed for targeted attacks and features a modular architecture with multiple loaders and encrypted file archives to enhance its capabilities and evade detection.
The infection process begins with a first-stage loader embedded with legitimate software, exploiting DLL sideloading to execute the loader. This loader then initiates a second-stage loader to activate the primary malware component. The file archive contains legitimate software, system components, and shellcode to facilitate module execution and communication via WebSockets.
Command-and-Control Capabilities
In one incident, a threat operator utilized the Impacket toolkit to deploy the malware from a shared network drive onto a targeted device after gaining access to the environment. The second-stage loader unpacks embedded data, which is a condensed version of a PE file in a custom format.
The main component of NeedyMantis manages command-and-control (C&C) communications through functions that establish and maintain a WebSockets connection. It transmits system and user data to the C&C and, based on instructions received, can dynamically load or unload modules, process data, and adjust settings.
Microsoft notes that while the primary component’s commands suggest the potential for expanded functionality through additional modules, the capabilities of these modules remain largely speculative.
As the cybersecurity landscape evolves, understanding and mitigating threats like NeedyMantis becomes crucial for protecting critical infrastructure and sensitive data worldwide.
