Microsoft has disclosed a previously undocumented malware family called NeedyMantis that attackers have used to maintain access inside already-compromised organizations, including telecommunications companies, universities, medical nonprofits, intergovernmental organizations and government contractors.
Microsoft Threat Intelligence describes NeedyMantis as a post-compromise framework: attackers deploy it after gaining access to a network, then use it to preserve that foothold and support further operations. Microsoft says activity involving the malware dates back to at least October 2025.
Researchers discovered NeedyMantis while investigating indicators connected to the earlier DAEMON Tools supply-chain compromise. One known operator, tracked by Microsoft as Storm-3069, has been linked to that campaign. Microsoft has not observed NeedyMantis itself being distributed through the compromised DAEMON Tools software, however. The malware appears later in an attack, after an intruder is already inside the victim’s environment.
Kaspersky disclosed the DAEMON Tools compromise in May 2026, reporting that trojanized versions of the software had been distributed from the vendor’s infrastructure beginning in April.
Built for post-compromise access
NeedyMantis uses several stages and can hide malicious DLL files alongside legitimate applications such as Poedit, curl, Vim and TightVNC. The malware uses DLL sideloading, a technique that tricks legitimate Windows software into loading attacker-controlled code. Its components also use encryption, compression, code obfuscation and anti-debugging techniques intended to make analysis more difficult.
Microsoft also found samples using filenames associated with Microsoft Office, Broadcom, Intel and Nvidia. That does not mean those companies’ software was compromised; the malware was simply made to resemble legitimate components.
In one observed intrusion, an attacker who was already inside the network used Impacket, a networking toolkit used by both security professionals and attackers, to copy NeedyMantis components to a target computer.
Once active, the malware communicates with attacker-controlled servers and can send information including the computer name, username and running processes. Its main component can also load additional modules, although Microsoft has not confirmed what capabilities those modules provide.
Microsoft sees links to China-based activity
Microsoft says observed NeedyMantis activity aligns with operations associated with China-based threat actors, citing selective deployment and targeting that corresponds with Chinese interests.
Storm-3069 is the only operator Microsoft has specifically identified using the malware, but researchers have also seen NeedyMantis activity outside that group’s known DAEMON Tools campaign. Microsoft has not attributed Storm-3069 to the Chinese government or determined whether every deployment involved the same operator.
For defenders, Microsoft recommends checking for connections to the observed command-and-control domain along with other endpoint and network indicators published in its report.
Because NeedyMantis normally appears after an attacker has already gained access, finding it should be treated as evidence of a potentially wider intrusion rather than an isolated malware infection and will require looking into how access was obtained, which systems were reached and what other activity occurred around the deployment.

Leave a Reply