Microsoft details China-linked NeedyMantis
Microsoft has publicly detailed the NeedyMantis malware framework, discovered during analysis of the May 2026 Daemon Tools supply chain attack.

Microsoft has traced the NeedyMantis malware to a compromised Daemon Tools update distributed in May 2026 that infected thousands of computers. The company identified the framework while pivoting from indicators linked to that supply chain compromise, which was first exposed by Kaspersky. Microsoft has now observed additional NeedyMantis activity beyond the initial campaign, indicating possible use by more than one operator.
Malware capabilities and infection chain
NeedyMantis is a modular post-compromise malware framework analyzed by Microsoft. Attackers deploy it only after they have already gained a foothold in a network, using it to maintain long-term access and support follow-on operations.
The infection chain starts with a first-stage loader and a file archive packaged with legitimate software. It abuses DLL sideloading to execute the loader. In the sample analyzed, the loader replaced WinSparkle.dll, the software update component of Poedit. The first-stage loader then extracts and runs a second-stage loader that launches the main malware component.
The file archive contains legitimate software components, a second-stage loader, malware configuration, a WebSockets-based communication DLL, and shellcode to load module DLLs. The second-stage loader extracts embedded data, decodes and decompresses it into a minimized PE file in a custom DLL format.
NeedyMantis has a modular architecture with multiple loaders, custom encrypted file archives, executable formats, C++ components, and x64 shellcode designed to evade detection. The main component manages command-and-control via ten functions. These establish and maintain a WebSockets connection, send system and user information, and can load, unload, or dispatch modules and toggle flags. Microsoft notes that the capabilities of additional modules loaded by NeedyMantis remain unconfirmed.
Observed targeting and activity
The malware has been used in intrusions against telecoms, government entities, universities, medical nonprofits, and contractors, with activity dating back to at least October 2025. Microsoft has seen NeedyMantis in intrusions outside the DAEMON Tools campaign. Those operations share targeting that aligns with Chinese interests and show a pattern of selective deployment. Kaspersky said the pattern showed "intentions to conduct the infection in a targeted manner."
In one observed incident, an operator used the Impacket toolkit during hands-on-keyboard activity. They copied legitimate software, a malicious DLL, and the file archive from a network share and executed it on a targeted device. The framework has surfaced in a small number of intrusions.
Threat actor links and assessment
Microsoft associates NeedyMantis with Storm-3069, a China-based group not attributed to a nation-state, and notes possible use by multiple operators. Storm-3069 is Microsoft’s temporary designator for the group behind the DAEMON Tools campaign. At the time of writing, Microsoft observed at least one threat actor using NeedyMantis: Storm-3069.
Microsoft assesses Storm-3069 activity originates from China but has not attributed it to a Chinese nation-state actor. Observed NeedyMantis activity aligns with threat actors operating from China. Microsoft said the tool "might be used by more than one operator" and has not determined if all observed activity is attributable to the same operator. The company continues to monitor its use in targeted intrusions.





