Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Analyzes NeedyMantis Malware from Daemon Tools Hack

Microsoft Analyzes NeedyMantis Malware from Daemon Tools Hack

Posted on September 29, 2026 By CWS

Microsoft has released an in-depth examination of a sophisticated malware framework known as NeedyMantis, attributed to a China-based cyber group. This framework has been implicated in attacks targeting telecommunications and government entities.

Discovery and Impact of NeedyMantis

The NeedyMantis framework came to light during the investigation of indicators of compromise linked to the May 2026 Daemon Tools supply chain attack. This incident led to the infection of thousands of systems via compromised Daemon Tools software distributed through the official website, with a backdoor installed on a select few. Targets included government, scientific, manufacturing, and retail sectors in Belarus, Russia, and Thailand.

Microsoft’s recent report provides an exhaustive breakdown of NeedyMantis, which is a modular post-compromise malware used by the Daemon Tools hackers for pinpointed assaults on universities, government contractors, telecom companies, as well as medical and intergovernmental organizations.

Technical Details and Deployment

NeedyMantis has been operational since at least October 2025, likely involving multiple China-based threat actors. The group responsible for the Daemon Tools attack, identified as Storm-3069, has not been officially linked to any Chinese state-sponsored entities. The malware is designed for targeted attacks and features a modular architecture with multiple loaders and encrypted file archives to enhance its capabilities and evade detection.

The infection process begins with a first-stage loader embedded with legitimate software, exploiting DLL sideloading to execute the loader. This loader then initiates a second-stage loader to activate the primary malware component. The file archive contains legitimate software, system components, and shellcode to facilitate module execution and communication via WebSockets.

Command-and-Control Capabilities

In one incident, a threat operator utilized the Impacket toolkit to deploy the malware from a shared network drive onto a targeted device after gaining access to the environment. The second-stage loader unpacks embedded data, which is a condensed version of a PE file in a custom format.

The main component of NeedyMantis manages command-and-control (C&C) communications through functions that establish and maintain a WebSockets connection. It transmits system and user data to the C&C and, based on instructions received, can dynamically load or unload modules, process data, and adjust settings.

Microsoft notes that while the primary component’s commands suggest the potential for expanded functionality through additional modules, the capabilities of these modules remain largely speculative.

As the cybersecurity landscape evolves, understanding and mitigating threats like NeedyMantis becomes crucial for protecting critical infrastructure and sensitive data worldwide.

Security Week News Tags:China-based threat actor, Cybersecurity, DAEMON Tools, government organizations, malware analysis, Microsoft, modular malware, NeedyMantis, supply chain attack, Telecommunications

Post navigation

Previous Post: Amsterdam Man Arrested in ShinyHunters Hacking Probe
Next Post: WatchGuard API Flaws Allow Command Execution

Related Posts

North Korea Utilizes New Linux Toolkit in Espionage North Korea Utilizes New Linux Toolkit in Espionage Security Week News
Cybersecurity Firm Magnitude Secures M for AI Risk Management Cybersecurity Firm Magnitude Secures $10M for AI Risk Management Security Week News
Palo Alto Networks Vulnerability Under Active Exploitation Palo Alto Networks Vulnerability Under Active Exploitation Security Week News
Palo Alto Networks Vulnerability Under Active Exploitation CoChat Introduces Platform to Manage Shadow AI Risks Security Week News
CrowdSec Confirms Source Code Breach in Recent Attack CrowdSec Confirms Source Code Breach in Recent Attack Security Week News
Cybersecurity Firm Magnitude Secures M for AI Risk Management Huskeys Secures $8 Million in Seed Funding for ESM Platform Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • WatchGuard API Flaws Allow Command Execution
  • Microsoft Analyzes NeedyMantis Malware from Daemon Tools Hack
  • Amsterdam Man Arrested in ShinyHunters Hacking Probe
  • Storm-3168’s Swift Azure Resource Deletion Exposes Security Gaps
  • OpenAI Halts Model Training After Security Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • WatchGuard API Flaws Allow Command Execution
  • Microsoft Analyzes NeedyMantis Malware from Daemon Tools Hack
  • Amsterdam Man Arrested in ShinyHunters Hacking Probe
  • Storm-3168’s Swift Azure Resource Deletion Exposes Security Gaps
  • OpenAI Halts Model Training After Security Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark