Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft
Microsoft dissected NeedyMantis, a modular backdoor Storm-3069 used after the Daemon Tools supply-chain attack.
Microsoft published a technical analysis of NeedyMantis, a modular post-compromise framework linked to the May 2026 Daemon Tools supply-chain attack. Poisoned installers from the official site infected thousands of computers, and a backdoor was deployed on roughly a dozen systems at government, scientific, manufacturing, and retail organizations in Belarus, Russia, and Thailand. Storm-3069, a China-based group not attributed to a nation-state, and possibly other Chinese actors have used NeedyMantis since at least October 2025 against universities, government contractors, telecoms, and medical and intergovernmental organizations. The chain uses DLL sideloading, custom encrypted archives, a WebSockets command-and-control channel with ten control functions, and Impacket for hands-on-keyboard deployment; module capabilities remain unconfirmed.