Microsoft has published a technical analysis of a malware family it calls NeedyMantis, used by attackers to keep long-term footholds inside networks they have already broken into. The tool has surfaced in a small number of highly targeted intrusions — not mass campaigns — hitting telecommunications providers, universities, medical nonprofits, intergovernmental organizations, and government contractors, with activity dating back to at least October 2025.
What happened
Microsoft's researchers found NeedyMantis while following up on a separate investigation into a supply-chain compromise of the DAEMON Tools Lite disk-imaging utility, where official, signed installers were quietly modified to carry malicious code between early April and early May 2026. Microsoft has not seen NeedyMantis itself distributed through that tampered installer — but it links use of the malware to a threat actor it tracks under the temporary designation Storm-3069, one of what may be several groups using the tool.
NeedyMantis arrives as a three-piece bundle: a copy of a legitimate, trusted program, a malicious DLL renamed to match a library that program already expects to load, and an encrypted archive sharing that same name. When the legitimate program starts, it unwittingly loads the malicious DLL instead — a classic DLL sideloading technique. Programs abused this way include a translation tool, a text editor, a remote-access utility, and curl, with the malware also disguising itself as library files from major hardware and software vendors.
Once loaded, the malicious DLL unpacks and decodes a further stage from the encrypted archive. That component then reaches out to a command-and-control server over HTTPS before switching to a WebSocket connection, through which operators can push and remove additional modules and move data — functionality Microsoft has not yet fully mapped. In one confirmed intrusion, an attacker who already had a foothold used the Impacket toolkit to copy the bundle from a network share onto a target machine, showing the malware is deployed post-compromise rather than used as an initial-access tool.
Microsoft assesses that the observed activity fits a pattern it associates with China-linked operations — narrowly targeted organizations aligning with Chinese strategic interests — though it stops short of formally attributing Storm-3069 to a state actor, and has not confirmed whether Storm-3069 is the same group tracked elsewhere in the industry in connection with the DAEMON Tools campaign.
Why it matters
NeedyMantis is not a mass-market commodity threat — it is being deployed sparingly, inside networks where an attacker already has a presence, specifically to keep that access alive and quiet over time. Its reliance on DLL sideloading inside legitimate, signed software makes it hard to catch with signature-based tools alone: a hit on a normal application file path doesn't by itself indicate infection, and file hashes need to be checked against known-good baselines. For the sectors named in the disclosure — telecoms, higher education, healthcare-adjacent nonprofits, intergovernmental bodies, and government contractors — this is a reminder that a single breach can translate into durable, hard-to-detect access unless post-compromise persistence is actively hunted for, not just the initial entry point.
What to do
- Check your environment against the published indicators of compromise: the file hashes for the malicious loader and encrypted archives, the command-and-control domain, and the hardcoded user agent string used by the malware's communications component.
- Don't rely on file-path matches alone — the abused DLL name is also a normal part of the legitimate software it impersonates, so compare any hit against known-good hashes before treating it as an infection.
- Run hunting queries across a wider-than-default window; published detection queries often only look back a matter of days, which won't catch files first seen months earlier unless the window is extended.
- Harden endpoint defenses with cloud-delivered protection, block-at-first-sight, EDR in block mode, network protection, automatic attack disruption, and relevant attack surface reduction rules, and monitor outbound traffic for connections to known command-and-control infrastructure regardless of endpoint tooling.
- If your organization used the affected disk-imaging utility during the compromised window, uninstall it, run a full system scan, and reinstall the current version from the official source.
- Treat this as a prompt to review post-compromise persistence detection generally — DLL sideloading through trusted, signed applications is a technique worth hunting for beyond this specific malware family.
