Hackers have deployed a malware family called NeedyMantis to maintain long-term access to networks they had already compromised, according to a technical analysis published by Microsoft. The malware has appeared in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use dates back to at least October 2025.

Microsoft discovered NeedyMantis while investigating indicators from Kaspersky's probe into the supply chain attack on DAEMON Tools, where official, signed installers for the DAEMON Tools Lite disk image program carried malicious code from April 8, 2026. The developer replaced them with a clean version on May 5. In the cases Microsoft examined, NeedyMantis arrived as a bundle of three parts: a copy of a legitimate program, a malicious DLL named after a file that program loads, and an encrypted archive with the same name as the DLL. The legitimate programs used this way include the Poedit translation tool, curl, the Vim text editor, and the TightVNC remote access tool. The malware has also posed as DLL files from Microsoft Office, Broadcom, Intel, and NVIDIA. In one intrusion, an operator who was already inside the network used the Impacket toolkit to copy the bundle from a network share and run it on a target machine.

Microsoft tracks the activity tied to the DAEMON Tools attack as Storm-3069, a temporary name the company gives to new or developing groups until it's confident about who is behind them or where they come from. The company says Storm-3069 is one group that uses NeedyMantis, though it hasn't seen the malware itself spread through a supply chain attack. Microsoft has also seen NeedyMantis outside Storm-3069's activity in the DAEMON Tools campaign and says more than one group may be using the malware. Storm-3069's activity appears to originate in China, Microsoft assesses, but the company hasn't tied the group to a Chinese nation-state actor. All the NeedyMantis activity Microsoft has seen so far fits the pattern of groups it links to China, including targets that align with Chinese interests and the malware's use against only a few selected organizations.

Once loaded, the DLL unpacks the next stage from the encrypted archive and runs it, which then decodes the malware's main component. The main component connects to a command-and-control server over HTTPS and then switches to a WebSocket connection, through which operators can load and unload extra modules and send data to them. Microsoft hasn't confirmed what those modules do. An older version, seen in October 2025, included a persistence module that uses Windows services, but Microsoft didn't describe how the newer version it analyzed stays on a machine. When Kaspersky disclosed the DAEMON Tools attack in May, it found Chinese-language text in the malware but didn't attribute it to any particular group. Google Threat Intelligence Group tracks the actor behind the DAEMON Tools campaign as UNC6863, and in June, Mandiant described UNC6863 as "a suspected China-nexus actor" that used the DAEMON Tools compromise to deploy malware.

Defenders can check their networks using the file hashes, domains, file paths, and hunting queries that Microsoft published, including SHA-256 hashes for the first-stage loader WinSparkle.dll and encrypted archives. Microsoft Defender Antivirus detects the malware as TrojanDropper:Win64/NeedyMantis and Behavior:Win64/NeedyMantis. Microsoft recommends several Defender settings, including cloud-delivered protection, block at first sight, EDR in block mode, network protection, automatic attack disruption, and two attack surface reduction rules. It also advises checking outbound traffic for connections to the command-and-control domain, a step that doesn't need Defender. Microsoft hasn't seen NeedyMantis arrive through the tampered DAEMON Tools installers; for those installers, the developer has advised that anyone who downloaded or installed the free DAEMON Tools Lite 12.5.1 during the affected period should uninstall it, run a full system scan, and download version 12.6 from the official website. Organizations that maintain persistent network access for legitimate remote tools may find themselves particularly vulnerable to this kind of DLL sideloading, where attackers disguise malicious code as trusted software components that security teams might overlook.