MICROSOFT Threat Intelligence has detailed NeedyMantis, a modular post‑compromise backdoor seen in targeted intrusions since at least October 2025. The malware hides inside trusted software via DLL sideloading, pairing a legitimate program with a malicious DLL so that Windows loads the fake DLL first. Poedit, curl, Vim, and TightVNC are among the legitimate apps observed carrying the loader, while the backdoor has also masqueraded as components of Microsoft Office, Broadcom, Intel, and NVIDIA. The operators typically deliver NeedyMantis after they have already gained initial access, rather than via a broad initial foothold.
Infection chains revolve around encrypted custom archives and a second-stage loader. A sideloaded DLL unpacks the next stage from a companion archive, then hands control to a PowerShell‑extension file containing raw x64 shellcode that unpacks the main component. The main component runs a stripped‑down executable format and communicates with a C2 server over HTTPS and then WebSockets, using RC4 to encrypt traffic.
The first check‑in returns a cookie‑smuggling data such as computer name, user name, running processes and installed programmes; subsequent WebSocket sessions support a limited set of commands to load or unload modules and relay data. Evidence links NeedyMantis to Storm‑3069, associated with the DAEMON Tools supply chain compromise; Microsoft notes the activity appears selective rather than broadly deployed, and Kaspersky’s DAEMON Tools work cites signs of a Chinese‑speaking adversary.
Defensive guidance from Microsoft includes hunting for DLLs loaded from odd ProgramData folders, flagging mismatched file extensions and content, watching for Impacket‑style remote execution, and auditing outbound WebSockets with unusual cookie data. They also recommend updating DAEMON Tools to a clean release and reviewing hosts that ran affected versions. The report emphasises that the first breach is only the start, urging defenders to hunt for remnants and artefacts left behind by attackers.