Skip to content

Security1 publisher2 min readPublished

NeedyMantis backdoor followed the Daemon Tools trojan onto a dozen targeted machines

Microsoft dissected NeedyMantis, the follow-on backdoor from May's Daemon Tools supply-chain attack that reached a dozen of the thousands of infected machines. Microsoft found it by tracing the campaign's indicators. Removing the poisoned installer does not clear it.

The Watch · Security desk

Illustration accompanying NeedyMantis backdoor followed the Daemon Tools trojan onto a dozen targeted machines

What happened

  • The trojanized Daemon Tools installers hit government, scientific, manufacturing and retail organizations across Belarus, Russia and Thailand.
  • In the targeted follow-on attacks, Microsoft says the same operators ran NeedyMantis against universities, government contractors, telecoms, medical non-profits and intergovernmental bodies.
  • NeedyMantis has been used in attacks since at least October 2025, and Microsoft says more than one China-based actor is likely running it.
  • Microsoft has not tied Storm-3069, the group behind the Daemon Tools compromise, to any Chinese government.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision The dozen backdoored hosts took hand-run Impacket deployment, so the response scope is the network the operator was already moving through, not just the infected endpoints.
  • constraint Microsoft could not confirm what NeedyMantis's loadable modules do, so a defender who finds the main component cannot bound what was collected or executed on that host.
  • exposure NeedyMantis predates this campaign by about seven months and is shared among China-based actors, so its indicators are worth hunting well beyond the Daemon Tools victims.

Microsoft puts NeedyMantis late in an intrusion. "Based on observed activity, NeedyMantis is typically deployed after a threat actor has already established access to a target environment, indicating that the malware is used to maintain long-term access and support follow-on operations," Microsoft said [7].

The delivery is done by hand. In one case an operator used the Impacket toolkit to stage the components. "In one observed incident, an operator used the Impacket toolkit during hands-on-keyboard activity to copy the legitimate software, malicious DLL, and file archive from a network share and execute it on a targeted device. This activity occurred after the actor had already obtained access to the environment," Microsoft said [11].

The chain runs on DLL sideloading. A first-stage loader ships next to legitimate software and a custom encrypted archive, abuses sideloading to run, and pulls out a second-stage loader that decodes and decompresses an embedded payload into a DLL written in a custom executable format before launching the main component [10]. That archive also carries the malware configuration, a WebSockets communication DLL and shellcode to load further modules [14]. The main component opens a WebSockets connection to its command server through ten dedicated functions, reports system and user details, and takes commands to load and unload modules and pass them data [12].

What those modules do is not established. "The main component's load, unload, and data dispatch commands show that NeedyMantis can extend its functionality through additional modules, but the capabilities of those modules remain unconfirmed," Microsoft said [13]. A host running the main component is confirmed reachable and controllable [12]. What ran through it afterward is not in the report [13].

What to watch

  • Whether Microsoft or others recover NeedyMantis modules and confirm what they collect or run, the missing piece for scoping an infection.
  • Whether Storm-3069 or the other China-based operators using NeedyMantis draw a nation-state attribution.
  • Whether victims outside Belarus, Russia and Thailand surface, given NeedyMantis was active before the May campaign.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories