Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
Microsoft reports NeedyMantis malware used by China-linked group for persistent network access since October 2025.
Summary
Microsoft has disclosed a malware family called NeedyMantis used for maintaining long-term access in breached networks at telecommunications, universities, medical nonprofits, and government contractors since October 2025. The malware uses DLL sideloading with legitimate programs and connects to C2 servers via HTTPS/WebSocket, with operators able to load and unload modules. Microsoft attributes the activity to Storm-3069, a likely China-nexus group, which was also linked to the DAEMON Tools supply chain compromise in April 2026.
Full text
Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks Swati KhandelwalSep 28, 2026Cyber Attack / Threat Intelligence Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use goes back to at least October 2025. Microsoft found NeedyMantis while following up on indicators from Kaspersky's investigation into the supply chain attack on DAEMON Tools. In that attack, official, signed installers for the DAEMON Tools Lite disk image program carried malicious code from April 8, 2026. The developer replaced them with a clean version on May 5. Microsoft tracks the activity tied to that attack as Storm-3069. It says Storm-3069 is one group that uses NeedyMantis, though it has not seen the malware itself spread through a supply chain attack. Defenders can check their networks using the file hashes, domains, file paths, and hunting queries that Microsoft published and listed below. How NeedyMantis Runs In the cases Microsoft examined, NeedyMantis arrived as a bundle of three parts: a copy of a legitimate program, a malicious DLL named after a file that program loads, and an encrypted archive with the same name as the DLL. When the program starts, it loads the malicious DLL. This is called DLL sideloading. The legitimate programs used this way include the Poedit translation tool, curl, the Vim text editor, and the TightVNC remote access tool. The malware has also posed as DLL files from Microsoft Office, Broadcom, Intel, and NVIDIA. In the sample Microsoft analyzed in detail, the malicious file replaced WinSparkle.dll, the update component that Poedit uses. In one intrusion, an operator who was already inside the network used the Impacket toolkit to copy the bundle from a network share and run it on a target machine. How attackers initially gain access to a network may differ from one intrusion to the next. Once loaded, the DLL unpacks the next stage from the encrypted archive and runs it. That stage decodes the malware's main component. The main component connects to a command-and-control (C2) server over HTTPS and then switches to a WebSocket connection. Through that connection, operators can load and unload extra modules and send data to them. Microsoft has not confirmed what those modules do. An older version, seen in October 2025, included a persistence module that uses Windows services. Microsoft did not describe how the newer version it analyzed stays on a machine. Who Is Behind It Storm-3069 is a temporary name. Microsoft gives "Storm" names to new or developing groups until it is confident about who is behind them or where they come from. Microsoft has also seen NeedyMantis outside Storm-3069's activity in the DAEMON Tools campaign, and it says more than one group may be using the malware. It has not determined whether all the activity comes from a single actor, nor has it explained what links Storm-3069 to NeedyMantis. Storm-3069's activity appears to originate in China, Microsoft assesses, but the company has not tied the group to a Chinese nation-state actor. All the NeedyMantis activity Microsoft has seen so far fits the pattern of groups it links to China. Examples include targets that align with Chinese interests and the malware's use against only a few selected organizations. When Kaspersky disclosed the DAEMON Tools attack in May, it found Chinese-language text in the malware but did not attribute it to any particular group. Google Threat Intelligence Group tracks the actor behind the DAEMON Tools campaign as UNC6863. In June, Mandiant described UNC6863 as "a suspected China-nexus actor" that used the DAEMON Tools compromise to deploy malware. It is unclear whether UNC6863 and Storm-3069 belong to the same group. How to Check for NeedyMantis Microsoft published these indicators of compromise: SHA-256: e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e (first-stage loader WinSparkle.dll, first seen May 21, 2026) SHA-256: 9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef (encrypted archive named WinSparkle, first seen May 23, 2026) SHA-256: c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77 (encrypted archive named libcurl, older version, first seen October 3, 2025) Domain: corp.tripswithengine[.]com (C2 server, port 443) User agent: firefox/21.0 (hard-coded in the malware's communications DLL) These are some of the file paths used by the malicious DLLs: %ProgramFiles%\Poedit\WinSparkle.dll %ProgramData%\USOShared\libcurl.dll %ProgramData%\VIM\vim64.dll %ProgramData%\TightVNC\VIM\vim64.dll %ProgramData%\office\dbghelp.dll %ProgramData%\broadcom\dbghelp.dll %ProgramData%\Intel\jli.dll %ProgramFiles%\modifiable\nvml.dll %ProgramData%\ics\nvml.dll Microsoft Defender Antivirus detects the malware as TrojanDropper:Win64/NeedyMantis and Behavior:Win64/NeedyMantis. Microsoft also published hunting queries that look for these paths in Defender XDR, and for the C2 domain and user agent in both Defender XDR and Microsoft Sentinel. Each query looks back only seven days. Microsoft has not said whether NeedyMantis is still in use, and the files it dated were first seen in October 2025 and May 2026. If run unchanged, the queries would not find events from those months. A hit on the Poedit path alone does not prove an infection. WinSparkle.dll is also a normal part of Poedit, so compare any file found there with the published hash. Microsoft recommends several Defender settings: cloud-delivered protection, block at first sight, EDR in block mode, network protection, automatic attack disruption, and two attack surface reduction rules. It also advises checking outbound traffic for connections to the C2 domain, a step that does not need Defender. Microsoft has not seen NeedyMantis arrive through the tampered DAEMON Tools installers. For those installers, the developer has advised that anyone who downloaded or installed the free DAEMON Tools Lite 12.5.1 during the affected period should uninstall it, run a full system scan, and download version 12.6 from the official website. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share SHARE Cyber Attack, Malware, Threat Intelligence, Windows Security ⚡ Top Stories This Week Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates New CVSS 10.0 VeloCloud
Indicators of Compromise
- malware — NeedyMantis
- malware — WinSparkle.dll