Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft
Microsoft analyzes NeedyMantis malware used by China-linked hackers after Daemon Tools supply chain attack.
Summary
Microsoft has detailed NeedyMantis, a modular post-compromise malware framework used by a China-based threat actor, Storm-3069. This framework was discovered following the May 2026 Daemon Tools supply chain attack, which infected thousands of computers. NeedyMantis is designed for long-term persistence and supports follow-on operations, utilizing a custom executable file format and DLL sideloading for evasion.
Full text
Microsoft has analyzed a malware framework used by a China-based threat actor in attacks against telecommunications and governmental organizations. Dubbed NeedyMantis, the framework was discovered during the follow-on analysis of indicators of compromise (IoCs) associated with the May 2026 Daemon Tools supply chain attack. Thousands of computers were infected through poisoned Daemon Tools iterations distributed through the official website, and a backdoor was deployed on roughly a dozen of them. Government, scientific, manufacturing, and retail organizations in Belarus, Russia, and Thailand were hit. In a fresh report, Microsoft provides a detailed analysis of NeedyMantis, the modular post-compromise malware the Daemon Tools hackers used in targeted attacks against universities, government contractors, and telecoms, as well as medical non-profit and intergovernmental organizations. “Based on observed activity, NeedyMantis is typically deployed after a threat actor has already established access to a target environment, indicating that the malware is used to maintain long-term access and support follow-on operations,” Microsoft notes. NeedyMantis has been used in attacks since at least October 2025, likely by more threat actors based in China. According to Microsoft, the hacking group behind the Daemon Tools attack, tracked as Storm-3069, has not been attributed to a Chinese nation-state actor.Advertisement. Scroll to continue reading. Used only in targeted attacks, the malware framework has a modular architecture consisting of multiple loaders, custom encrypted file archives and executable file formats, and modular components in C++ and x64 shellcode, designed to evade detection and expand capabilities. The NeedyMantis infection chain starts with a first-stage loader and a file archive packaged alongside legitimate software. It abuses DLL sideloading to execute the loader, which in turn extracts and runs a second-stage loader to execute the main malware component. The file archive contains multiple legitimate software and system components, a second-stage loader, the malware configuration, a WebSockets-based communication DLL, and shellcode to load module DLLs and resolve exports. “In one observed incident, an operator used the Impacket toolkit during hands-on-keyboard activity to copy the legitimate software, malicious DLL, and file archive from a network share and execute it on a targeted device. This activity occurred after the actor had already obtained access to the environment,” Microsoft says. The second-stage loader extracts embedded data and decodes and decompresses it. The resulting data is a minimized version of a PE file, in the form of a DLL formatted using a custom executable file format. NeedyMantis’ main component orchestrates command-and-control (C&C) communication through 10 functions designed to initiate and maintain a WebSockets connection. It also sends system and user information to the C&C, and, based on received commands, can load or unload modules, dispatch data to modules, and turn off flags. “The main component’s load, unload, and data dispatch commands show that NeedyMantis can extend its functionality through additional modules, but the capabilities of those modules remain unconfirmed,” Microsoft notes. Related: Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign Related: Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability Related: New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining Related: Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Kiteworks Urges Server Shutdown, Finds Advanced Forms VulnerabilityNew x47.c Windows Botnet Weaponizes xAI Grok, AI API DrainingKosovar Owner of Rydox Marketplace Pleads Guilty in US Court‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data ExfiltrationRoundcube Webmail Vulnerability in Attackers’ CrosshairsKontext Security Emerges With $4 Million for AI Agent Runtime ControlsAI-Powered Campaign Targets Hundreds of Online RetailersSolarWinds Patches Critical RCE Flaws in Observability Self-Hosted Latest News Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’ Modulate Raises $25 Million to Advance Deepfake DetectionCall for Presentations Open for 2026 CISO Forum Virtual SummitPrison Sentence for Former US Soldier Who Hacked AT&T and VerizonDC Health Agency Exposes 400,000 Beneficiary RecordsGoogle Warns of ShinyHunters’ Fresh Oracle PeopleSoft CampaignNew Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy ProtectionsNvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveDoppel has named Joey Rachid as Chief Security Advisor and Field Chief Information Security Officer.Delinea has appointed Timothy Regan as Chief Financial Officer.Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.More People On The MoveExpert Insights Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- malware — NeedyMantis