Security1 publisher2 min readPublished
NeedyMantis was in targeted networks six months before DAEMON Tools installers were poisoned
Microsoft says intruders have used NeedyMantis, a sideloaded malware family, to hold access in a few targeted networks since at least October 2025. It has not seen the tool ship in the poisoned DAEMON Tools installers, so its indicators apply beyond that software's users.
The Watch · Security desk

What happened
- Signed DAEMON Tools Lite installers carried malicious code from April 8, 2026, until the developer replaced them with a clean version on May 5.
- Microsoft found NeedyMantis while following up on indicators from Kaspersky's investigation of that installer compromise.
- Storm-3069, Microsoft's name for the installer attackers, is one user of NeedyMantis, and Microsoft has seen the malware outside that group's activity.
- In one intrusion, an operator already inside the network used Impacket to copy the NeedyMantis bundle from a share and run it on a target machine.
- Storm-3069 appears to operate from China, Microsoft assesses, though it has not tied the group to a Chinese nation-state actor.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint A hunt limited to hosts that ran DAEMON Tools Lite during the bad-installer window would miss NeedyMantis activity that Microsoft's own indicators date 187 days earlier.
- exposure Telecoms, universities, medical nonprofits, intergovernmental bodies and government contractors carry the exposure Microsoft documented, whether or not they ever installed DAEMON Tools.
- constraint File-name checks will not flag the loader, because it borrows DLL names from Office, Broadcom, Intel and NVIDIA and sits beside genuine copies of curl, Vim, Poedit or TightVNC.
- decision A NeedyMantis hit sends responders back to an earlier foothold, since the operator was already inside and Microsoft says initial access varies by intrusion.
The indicator dates put NeedyMantis on both sides of the DAEMON Tools compromise. The oldest item Microsoft published is an encrypted archive named libcurl from an older build, first seen October 3, 2025 [23]. It predates the first poisoned installers by 187 days [2]. The loader Microsoft took apart in detail, a malicious WinSparkle.dll, was first seen May 21, 2026 [21]. The developer had shipped the clean installer 16 days earlier [1]. The loader's encrypted archive appeared on May 23 [22]. Neither date falls inside the 27-day installer window [3].
WinSparkle is the update component the Poedit translation tool loads [10]. The attacker drops three files together: a genuine copy of the host program, a malicious DLL named after a library that program loads, and an encrypted archive carrying the DLL's name [8]. When the program starts, it loads the attacker's DLL [8]. The DLL unpacks a second stage from the archive. That stage decodes the main component, which connects to its command server over HTTPS and then switches to a WebSocket [12]. Over that channel operators can load and unload modules and send them data. Microsoft has not confirmed what the modules do [13].
Persistence is documented only for the old build. The October 2025 version had a module that used Windows services, and Microsoft did not describe how the newer version stays on a machine [14]. A hunt for suspicious service creation covers the older build. For the May build, defenders have the file and network indicators [14].
The files match on SHA-256. The WinSparkle.dll loader is e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e [21]. The WinSparkle archive is 9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef [22]. The older libcurl archive is c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77 [23]. On the network, the malware calls corp.tripswithengine[.]com on port 443 [24] with a hard-coded user agent of firefox/21.0 [25]. Microsoft's release also includes file paths and hunting queries [7].
Storm-3069 is a working name. Microsoft assigns Storm labels to new or developing groups until it is confident who is behind them or where they come from [15]. When Kaspersky disclosed the installer attack in May, it found Chinese-language text in the malware and did not attribute it to a group [18]. Google Threat Intelligence Group tracks the DAEMON Tools actor as UNC6863. In June, Mandiant described UNC6863 as "a suspected China-nexus actor" that used the compromise to deploy malware [19]. Whether UNC6863 and Storm-3069 are the same group is unclear [20].
What to watch
- Microsoft or another vendor documenting what the NeedyMantis modules do, or how the newer build stays on a machine.
- Evidence that UNC6863 and Storm-3069 are one group, or Microsoft explaining what ties Storm-3069 to NeedyMantis.
- A NeedyMantis sample found on a host whose only entry point was a poisoned DAEMON Tools installer, which would tie the installer window to this malware.