Microsoft Dissects NeedyMantis Malware Used in Daemon Tools Attacks
Share
Microsoft has released a detailed analysis of NeedyMantis, a modular malware framework used by China-based threat actors to maintain long-term access within compromised environments.
The discovery of the framework follows investigations into the May 2026 Daemon Tools supply chain attack. During that incident, thousands of computers were infected via poisoned iterations of Daemon Tools software distributed through its official website.
Modular Architecture and Persistence
Microsoft’s research indicates that NeedyMantis is designed for post-compromise operations. It is typically deployed after an attacker has already established an initial foothold, serving to maintain access and support subsequent operations.
The malware employs a modular architecture featuring multiple loaders, custom encrypted file archives, and specific executable file formats. The infection chain begins with a first-stage loader that uses DLL sideloading to execute a second-stage loader, which then runs the primary malware component.
To evade detection, the main component uses a custom executable file format. This involves a minimised version of a Portable Executable (PE) file, formatted as a DLL, which is decoded and decompressed from embedded data.
Targeted Sectors and Attribution
The threat actor behind these operations is tracked as Storm-3069. This group has targeted various sectors, including telecommunications, government agencies, universities, and medical non-profit organisations. Microsoft noted that specific attacks have impacted entities in Belarus, Russia, and Thailand.
While the group is identified as being based in China, Microsoft stated that Storm-3069 has not yet been formally attributed to a Chinese nation-state actor. The framework has been observed in active use since at least October 2025.
NeedyMantis manages command-and-control (C2) communications through ten distinct functions designed to maintain WebSockets connections. The main component is capable of loading or unloading additional modules, allowing attackers to dynamically adjust their capabilities within a target network.




Leave a Reply