Download Privacy Needle App

Type to search

Cybersecurity

Microsoft Dissects NeedyMantis Malware Used in Daemon Tools Attacks

Share

Microsoft has released a detailed analysis of NeedyMantis, a modular malware framework used by China-based threat actors to maintain long-term access within compromised environments.

The discovery of the framework follows investigations into the May 2026 Daemon Tools supply chain attack. During that incident, thousands of computers were infected via poisoned iterations of Daemon Tools software distributed through its official website.

Modular Architecture and Persistence

Microsoft’s research indicates that NeedyMantis is designed for post-compromise operations. It is typically deployed after an attacker has already established an initial foothold, serving to maintain access and support subsequent operations.

The malware employs a modular architecture featuring multiple loaders, custom encrypted file archives, and specific executable file formats. The infection chain begins with a first-stage loader that uses DLL sideloading to execute a second-stage loader, which then runs the primary malware component.

To evade detection, the main component uses a custom executable file format. This involves a minimised version of a Portable Executable (PE) file, formatted as a DLL, which is decoded and decompressed from embedded data.

Targeted Sectors and Attribution

The threat actor behind these operations is tracked as Storm-3069. This group has targeted various sectors, including telecommunications, government agencies, universities, and medical non-profit organisations. Microsoft noted that specific attacks have impacted entities in Belarus, Russia, and Thailand.

While the group is identified as being based in China, Microsoft stated that Storm-3069 has not yet been formally attributed to a Chinese nation-state actor. The framework has been observed in active use since at least October 2025.

NeedyMantis manages command-and-control (C2) communications through ten distinct functions designed to maintain WebSockets connections. The main component is capable of loading or unloading additional modules, allowing attackers to dynamically adjust their capabilities within a target network.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.