Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft
Microsoft dissected NeedyMantis, a modular backdoor Storm-3069 used after the Daemon Tools supply-chain attack.
Microsoft published a technical analysis of NeedyMantis, a modular post-compromise framework linked to the May 2026 Daemon Tools supply-chain attack. Poisoned installers from the official site infected thousands of computers, and a backdoor was deployed on roughly a dozen systems at government, scientific, manufacturing, and retail organizations in Belarus, Russia, and Thailand. Storm-3069, a China-based group not attributed to a nation-state, and possibly other Chinese actors have used NeedyMantis since at least October 2025 against universities, government contractors, telecoms, and medical and intergovernmental organizations. The chain uses DLL sideloading, custom encrypted archives, a WebSockets command-and-control channel with ten control functions, and Impacket for hands-on-keyboard deployment; module capabilities remain unconfirmed.
- Microsoft analyzed NeedyMantis, a modular post-compromise malware framework.
- Poisoned Daemon Tools installers infected thousands; a backdoor reached about a dozen systems.
- Storm-3069 is China-based but not attributed to a nation-state actor.
- The chain uses DLL sideloading, custom archives, and WebSockets command-and-control.
- Targets include telecoms, governments, universities, contractors, and nonprofits since October 2025.
Full article511 words · extracted from securityweek.com · click to collapse
Microsoft has analyzed a malware framework used by a China-based threat actor in attacks against telecommunications and governmental organizations.
Dubbed NeedyMantis, the framework was discovered during the follow-on analysis of indicators of compromise (IoCs) associated with the May 2026 Daemon Tools supply chain attack.
Thousands of computers were infected through poisoned Daemon Tools iterations distributed through the official website, and a backdoor was deployed on roughly a dozen of them. Government, scientific, manufacturing, and retail organizations in Belarus, Russia, and Thailand were hit.
In a fresh report, Microsoft provides a detailed analysis of NeedyMantis, the modular post-compromise malware the Daemon Tools hackers used in targeted attacks against universities, government contractors, and telecoms, as well as medical non-profit and intergovernmental organizations.
“Based on observed activity, NeedyMantis is typically deployed after a threat actor has already established access to a target environment, indicating that the malware is used to maintain long-term access and support follow-on operations,” Microsoft notes.
NeedyMantis has been used in attacks since at least October 2025, likely by more threat actors based in China. According to Microsoft, the hacking group behind the Daemon Tools attack, tracked as Storm-3069, has not been attributed to a Chinese nation-state actor.
Advertisement. Scroll to continue reading.
Used only in targeted attacks, the malware framework has a modular architecture consisting of multiple loaders, custom encrypted file archives and executable file formats, and modular components in C++ and x64 shellcode, designed to evade detection and expand capabilities.
The NeedyMantis infection chain starts with a first-stage loader and a file archive packaged alongside legitimate software. It abuses DLL sideloading to execute the loader, which in turn extracts and runs a second-stage loader to execute the main malware component.
The file archive contains multiple legitimate software and system components, a second-stage loader, the malware configuration, a WebSockets-based communication DLL, and shellcode to load module DLLs and resolve exports.
“In one observed incident, an operator used the Impacket toolkit during hands-on-keyboard activity to copy the legitimate software, malicious DLL, and file archive from a network share and execute it on a targeted device. This activity occurred after the actor had already obtained access to the environment,” Microsoft says.
The second-stage loader extracts embedded data and decodes and decompresses it. The resulting data is a minimized version of a PE file, in the form of a DLL formatted using a custom executable file format.
NeedyMantis’ main component orchestrates command-and-control (C&C) communication through 10 functions designed to initiate and maintain a WebSockets connection. It also sends system and user information to the C&C, and, based on received commands, can load or unload modules, dispatch data to modules, and turn off flags.
“The main component’s load, unload, and data dispatch commands show that NeedyMantis can extend its functionality through additional modules, but the capabilities of those modules remain unconfirmed,” Microsoft notes.
Related: Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
Related: Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability
Related: New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
Related: Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer