Microsoft Threat Intelligence on 28 September 2026 disclosed NeedyMantis, a modular malware framework that attackers deploy only after they already have a foothold in a network, and said it has surfaced in a small number of intrusions against telecommunications firms, universities, medical nonprofits, intergovernmental organizations and government contractors.
The activity dates back to at least October 2025 and matches what Microsoft associates with threat actors operating from China, although the company has not tied every incident to a single group.
Microsoft found the malware while pivoting from indicators linked to the DAEMON Tools supply chain compromise that Kaspersky exposed earlier this year. According to Microsoft’s analysis, at least one actor uses NeedyMantis: Storm-3069, the company’s temporary designator for the group behind the DAEMON Tools campaign. Microsoft assesses that Storm-3069 operates from China but has not attributed it to a Chinese nation-state actor.
Microsoft has also seen NeedyMantis in intrusions outside the DAEMON Tools campaign, and said the tool “might be used by more than one operator.” Those operations share targeting that aligns with Chinese interests and a pattern of selective deployment. Microsoft did not name any victims, their countries or how many organizations were hit.
The link to DAEMON Tools is narrower than it first appears. Kaspersky reported in May that attackers had served signed, trojanized installers of the disk-imaging software from its official website since 8 April 2026, profiling thousands of machines but sending a backdoor to only about a dozen government, scientific, manufacturing and retail systems in Russia, Belarus and Thailand.
Kaspersky said the pattern showed “intentions to conduct the infection in a targeted manner.” Microsoft says it has not seen NeedyMantis itself delivered through a supply chain compromise, only that supply chain access is one route an actor could use to reach the point where the malware is installed.
How NeedyMantis gets in and hides
NeedyMantis starts with a first-stage loader that abuses DLL sideloading, a technique in which a legitimate program is tricked into loading a malicious library that carries the name of one it expects. In the sample Microsoft analyzed, the loader replaced WinSparkle.dll, the software update component of the Poedit translation tool. Other variants hid behind curl, Vim and TightVNC, or posed as Microsoft Office, Broadcom, Intel and NVIDIA components in folders such as ProgramData\USOShared and ProgramData\Intel.
In one intrusion, an operator used the Impacket toolkit during hands-on keyboard activity to copy the legitimate software, the malicious DLL and an encrypted archive from a network share onto a target machine. That archive uses a custom compressed format whose keys and offsets change from sample to sample. The analyzed copy held 11 files, including genuine 7-Zip and Sysinternals components alongside malicious files disguised as Windows libraries such as dnsapi.dll and ws2_32.dll.
The second-stage loader, named encryptbase64.ps1, carries a PowerShell extension but contains x64 shellcode. It unpacks the main component, which is stored in a stripped-down custom version of the Windows executable format to frustrate analysis tools.
The main component contacts its command-and-control (C2) server at corp.tripswithengine[.]com over HTTPS, hiding the computer name, username and running processes in a cookie header. It then switches the connection to WebSockets and an RC4-encrypted binary protocol, using a hard-coded “firefox/21.0” user agent. Its own command set is small. It can load, unload and feed data to additional modules, and Microsoft said the capabilities of those modules remain unconfirmed.
What defenders should check
Microsoft advises organizations to look for outbound traffic to corp.tripswithengine[.]com and the Firefox/21.0 user agent, and to check for the sideloaded DLL names in unexpected folders.
It has published hunting queries for Defender XDR and Sentinel. Defender detects the malware as TrojanDropper:Win64/NeedyMantis and Behavior:Win64/NeedyMantis. The company also recommends running endpoint detection and response (EDR) in block mode and enabling attack surface reduction rules that block obfuscated scripts and rare executables. Anyone who installed DAEMON Tools versions 12.5.0.2421 to 12.5.0.2434 should move to 12.6.0.2445 or later, which Kaspersky says no longer contains the malicious code.
Community Discussion
Join the conversation. Ask questions, share solutions, and help others.
Be the first to start the discussion!
