NeedyMantis Malware: A Persistent Threat Targeting Critical Infrastructure
A new malware family, dubbed **NeedyMantis** by **Microsoft**, has been identified as a tool for maintaining long-term access to compromised networks. While not a supply chain attack itself, its use has been linked to activity observed during the **DAEMON Tools** supply chain compromise, raising concerns among IT security professionals and privacy-conscious users.
Hackers are leveraging a sophisticated malware family known as **NeedyMantis** to establish and sustain prolonged access within already breached networks, according to a recent technical analysis by **Microsoft**.
This malware has been observed in a limited number of highly targeted intrusions affecting diverse sectors, including telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its operational history stretches back to at least October 2025.
**Microsoft**'s discovery of **NeedyMantis** emerged during their follow-up investigations into indicators from **Kaspersky**'s probe into the **DAEMON Tools** supply chain attack. In that incident, official, signed installers for the **DAEMON Tools Lite** disk image program were found to contain malicious code from April 8, 2026, before being replaced with a clean version on May 5.
**Microsoft** tracks the activity associated with the **DAEMON Tools** attack under the temporary designation **Storm-3069**. While **Storm-3069** is identified as one group utilizing **NeedyMantis**, the malware itself has not been observed spreading via a supply chain attack. Defenders can proactively scrutinize their networks using the file hashes, domains, file paths, and hunting queries provided by **Microsoft**.

### How NeedyMantis Operates
In the cases analyzed by **Microsoft**, **NeedyMantis** is typically delivered as a three-part bundle: a legitimate program, a malicious DLL named after a file that the legitimate program loads, and an encrypted archive bearing the same name as the DLL. This technique, known as DLL sideloading, allows the malicious DLL to be loaded when the legitimate program is executed.
Legitimate programs exploited in this manner include the **Poedit** translation tool, **curl**, the **Vim** text editor, and the **TightVNC** remote access tool. The malware has also been observed masquerading as DLL files from reputable vendors such as **Microsoft Office**, **Broadcom**, **Intel**, and **NVIDIA**.
In a detailed sample analyzed by **Microsoft**, the malicious file replaced **WinSparkle.dll**, the update component used by **Poedit**.
One observed intrusion involved an operator, already present within the network, using the **Impacket** toolkit to copy the malware bundle from a network share and execute it on a target machine. The initial access vector for attackers may vary across different intrusions.
Upon successful loading, the malicious DLL unpacks and executes the next stage from the encrypted archive. This subsequent stage then decodes and runs the malware's main component. The main component establishes a connection to a command-and-control (C2) server over HTTPS, subsequently transitioning to a WebSocket connection.
This C2 connection enables operators to load and unload additional modules and transmit data to them. The specific functionalities of these modules have not yet been confirmed by **Microsoft**.
An earlier version of **NeedyMantis**, identified in October 2025, included a persistence module that leveraged Windows services. **Microsoft**'s analysis of newer versions did not elaborate on their persistence mechanisms.
### Attribution and Origin
**Storm-3069** is a provisional designation. **Microsoft** assigns "Storm" names to nascent or evolving threat groups until a confident attribution or origin can be established.
**NeedyMantis** activity has also been observed outside the scope of **Storm-3069**'s involvement in the **DAEMON Tools** campaign, suggesting that multiple groups may be employing this malware. **Microsoft** has not definitively determined if all observed activity stems from a single actor, nor has it clarified the precise link between **Storm-3069** and **NeedyMantis**.
**Microsoft** assesses that **Storm-3069**'s activity appears to originate from China. However, the company has refrained from directly attributing the group to a Chinese nation-state actor. All **NeedyMantis** activity observed thus far aligns with patterns typically associated with groups linked to China, including targeting that aligns with Chinese interests and the malware's selective deployment against a limited number of organizations.
When **Kaspersky** disclosed the **DAEMON Tools** attack in May, it noted the presence of Chinese-language text within the malware but did not attribute it to a specific group.
**Google Threat Intelligence Group** tracks the actor behind the **DAEMON Tools** campaign as **UNC6863**. In June, **Mandiant** described **UNC6863** as a "suspected China-nexus actor" that exploited the **DAEMON Tools** compromise to deploy malware. It remains unclear whether **UNC6863** and **Storm-3069** represent the same threat group.
### Indicators of Compromise for NeedyMantis
**Microsoft** has published the following indicators of compromise (IoCs):
* **SHA-256**: `e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e` (first-stage loader **WinSparkle.dll**, first seen May 21, 2026)
* **SHA-256**: `9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef` (encrypted archive named **WinSparkle**, first seen May 23, 2026)
* **SHA-256**: `c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77` (encrypted archive named **libcurl**, older version, first seen October 3, 2025)
* **Domain**: `corp.tripswithengine[.]com` (C2 server, port 443)
* **User agent**: `firefox/21.0` (hard-coded in the malware's communications DLL)
These are some of the file paths utilized by the malicious DLLs:
* `%ProgramFiles%\Poedit\WinSparkle.dll`
* `%ProgramData%\USOShared\libcurl.dll`
* `%ProgramData%\VIM\vim64.dll`
* `%ProgramData%\TightVNC\VIM\vim64.dll`
* `%ProgramData%\office\dbghelp.dll`
* `%ProgramData%\broadcom\dbghelp.dll`
* `%ProgramData%\Intel\jli.dll`
* `%ProgramFiles%\modifiable\nvml.dll`
* `%ProgramData%\ics\nvml.dll`
**Microsoft Defender Antivirus** detects this malware as `TrojanDropper:Win64/NeedyMantis` and `Behavior:Win64/NeedyMantis`. **Microsoft** has also released hunting queries for these paths in **Defender XDR**, and for the C2 domain and user agent in both **Defender XDR** and **Microsoft Sentinel**.
It's important to note that each query currently looks back only seven days. Given that the dated files were first observed in October 2025 and May 2026, running these queries unchanged would not identify events from those earlier months. While a hit on the **Poedit** path alone does not conclusively prove an infection (as **WinSparkle.dll** is a legitimate component of **Poedit**), any file found there should be cross-referenced with the published hash.
**Microsoft** recommends implementing several **Defender** settings, including cloud-delivered protection, block at first sight, EDR in block mode, network protection, automatic attack disruption, and two attack surface reduction rules. Furthermore, checking outbound traffic for connections to the C2 domain is advised, a step that does not require **Defender**.
It is crucial to reiterate that **Microsoft** has not observed **NeedyMantis** being delivered via the tampered **DAEMON Tools** installers. For those affected by the **DAEMON Tools** compromise, the developer has recommended that anyone who downloaded or installed the free **DAEMON Tools Lite 12.5.1** during the specified period should uninstall it, perform a comprehensive system scan, and download version 12.6 from the official website.