www.securityweek.com 29 Sept 2026, 09:46 UTC

Microsoft Uncovers NeedyMantis Malware Used in Targeted Attacks

Microsoft Uncovers NeedyMantis Malware Used in Targeted Attacks
CyberSIXT Evidence Panel
Threat Actor
Storm-3069

MICROSOFT has analysed NeedyMantis, a modular post-compromise malware framework used in targeted attacks against telecommunications, government, university, contractor, medical non-profit and intergovernmental organisations. The investigation followed analysis of indicators linked to the May 2026 Daemon Tools supply-chain attack, in which poisoned versions distributed through the official website infected thousands of computers.

A backdoor was deployed on roughly a dozen systems, affecting organisations in Belarus, Russia and Thailand across government, scientific, manufacturing and retail sectors. Microsoft says NeedyMantis has been used since at least October 2025, probably by multiple China-based threat actors. The Daemon Tools operator, tracked as Storm-3069, has not been attributed to a Chinese nation-state actor.

The framework is designed to maintain long-term access after an attacker has entered an environment. Its infection chain uses legitimate software, custom encrypted archives and DLL sideloading: a first-stage loader extracts a second-stage loader, which then launches the main component. The archive can contain legitimate system components, configuration data, a WebSockets communication DLL and shellcode for loading modules.

In one incident, Microsoft observed hands-on-keyboard activity using the Impacket toolkit to copy the files from a network share and execute them after access had already been obtained. The main component communicates with command-and-control infrastructure, sends system and user information, and can load or unload modules and dispatch data to them. Microsoft says the framework’s modular design could extend its capabilities, but those additional functions remain unconfirmed.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline