Hackers Leverage NeedyMantis Malware for Extended Network Infiltration
Microsoft has unveiled the use of a malware variant known as NeedyMantis, employed by hackers to secure prolonged access to compromised networks, according to a recent technical analysis. This malware has been detected in a limited number of targeted attacks against entities including telecommunications companies, academic institutions, medical nonprofit organizations, intergovernmental groups, and government contractors, with its origins traceable back to at least October 2025.
NeedyMantis surfaced during Microsoft’s investigation connected to indicators from Kaspersky’s analysis of a recent supply chain attack involving DAEMON Tools. Official installers of the DAEMON Tools Lite disk imaging software had been compromised with malicious code introduced on April 8, 2026, until the developer restored a clean version on May 5 of the same year.
Microsoft identifies this campaign as Storm-3069, indicating that various actors, including NeedyMantis operatives, are likely involved. However, no evidence has emerged to suggest that the malware propagates through supply chain vectors. Organizations can assess their security posture against this threat by utilizing specific file hashes, domain information, and hunting queries provided in Microsoft’s findings.
In the analyzed cases, NeedyMantis operates through a multi-part payload, which is characterized by the bundling of a legitimate program, a malicious DLL masquerading as a critical file the legitimate application loads, and an encrypted archive bearing the same name as the DLL. The malware leverages DLL sideloading techniques to infiltrate target systems upon launching the associated legitimate program, such as Poedit, curl, Vim, or TightVNC. Moreover, its disguise extends to files mimicking those from Microsoft Office, Broadcom, Intel, and NVIDIA.
One documented instance involves an intruder already within a system using the Impacket toolkit to transfer the malicious payload from a shared network location to the targeted machine. The methods through which attackers initially breach networks can vary from attack to attack, demonstrating a range of initial access vectors.
Once executed, the malicious DLL accesses and launches the next phase of the malware from its encrypted archive, which subsequently decodes the core component. This component establishes a connection to a command-and-control (C2) server over HTTPS, later transitioning to a WebSocket connection for real-time operations management, including module loading and unloading, as well as data transfer.
Analysis reveals that Storm-3069 likely has its roots in China, yet Microsoft has refrained from linking the group to specific state-sponsored activities. Instances of NeedyMantis outside the Storm-3069 context have also been identified, with evidence suggesting that multiple groups may be utilizing this malware, although the exact affiliations and operational methods remain ambiguous.
To counteract NeedyMantis, Microsoft has published a series of indicators of compromise along with specific file paths linked to the malware’s operations. Notably, the malicious payloads persist in locations associated with popular legitimate software. It is crucial for organizations to verify the legitimacy of files against published hash values to distinguish between compromised and uninfected system components.
Microsoft Defender Antivirus detects NeedyMantis as TrojanDropper:Win64/NeedyMantis and Behavior:Win64/NeedyMantis, while also suggesting comprehensive security measures including cloud-delivered protection and monitoring outbound traffic for connections to the identified C2 domain. Given that the NeedyMantis malware has not been explicitly linked to the altered DAEMON Tools installers, users of the affected software should remain vigilant and follow the developer’s guidance for uninstallation and system scanning.
As the threat landscape evolves, maintaining an understanding of current vulnerabilities and the tactics employed by adversaries, such as those defined in the MITRE ATT&CK framework, is essential for organizations aiming to protect their networks from sophisticated cyber threats.