Skip to content

Security1 publisher2 min readPublished

Microsoft links post-compromise NeedyMantis malware to the DAEMON Tools supply-chain actor

Microsoft says China-aligned NeedyMantis malware, active since at least October 2025, is installed after attackers already have access, to keep it long term. Because entry routes vary, organisations in the five sectors it targets need to look for copies already installed.

The Watch · Security desk

Illustration accompanying Microsoft links post-compromise NeedyMantis malware to the DAEMON Tools supply-chain actor

What happened

  • NeedyMantis surfaced while Microsoft pivoted from indicators tied to the DAEMON Tools supply-chain compromise, a campaign Kaspersky had already reported on.
  • Other NeedyMantis activity sits outside the DAEMON Tools campaign, and Microsoft says more than one operator might be using the malware.
  • Microsoft assesses that Storm-3069 operates from China but has not attributed it to a Chinese nation-state actor.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Intrusions in the five sectors that were cleaned up since October 2025 are open again, because NeedyMantis goes in after initial access and its job is to keep that access.
  • constraint Application allowlists that approve Poedit, curl, Vim or TightVNC by name will let the sideloaded loader run inside a process the policy already trusts.
  • decision Outside the five sectors, Microsoft's account of limited, selective deployment supports a single sweep of its published indicators and no dedicated incident-response effort.

The operator who installs NeedyMantis already has a foothold. Microsoft says the way attackers get in before the malware arrives may vary across intrusions [14]. A check against the DAEMON Tools indicators covers one known route, the one tied to Storm-3069 [9]. It does not cover the NeedyMantis activity Microsoft has seen outside that campaign [11].

A hunt starts with legitimate software carrying a DLL it should not have [16]. NeedyMantis begins with a first-stage loader and a file archive, packaged next to a real program. The loader poses as a DLL that program requires and is loaded through sideloading [15][16]. Microsoft lists Poedit, curl, Vim and TightVNC among the open-source programs abused this way [17]. Other samples borrow the names of Microsoft Office, Broadcom, Intel and NVIDIA DLL components [18].

Later stages are built to resist analysis [7]. Microsoft says the framework combines multiple loaders, custom encrypted archives, a custom executable file format and add-on modules, and that the design lets operators evade analysis and extend the malware's functions [7]. The components are written in C++ and x64 shellcode [15]. Microsoft has published indicators of compromise, Microsoft Defender detections and mitigation guidance [8].

Microsoft's China alignment rests on two observations: targeting that fits Chinese interests, and selective deployment [12]. It has not determined whether all the activity comes from one operator or whether several actors have access to the malware [6]. If several do, the DAEMON Tools indicators describe only one of them, and the other intrusions Microsoft has seen would need their own [6][11].

Microsoft describes a limited number of targeted operations and says the victim list points to selective deployment [1][13]. The sectors are telecommunications, universities, medical nonprofits, intergovernmental organisations and government contractors [2]. For those five, the search window runs back to at least October 2025 [4][1].

What to watch

  • Whether Microsoft assigns the NeedyMantis activity seen outside the DAEMON Tools campaign to Storm-3069, a second designator, or a named group.
  • Whether Microsoft or Kaspersky publish the initial access routes used in the non-DAEMON Tools intrusions.
  • Whether Microsoft attributes Storm-3069 to a Chinese nation-state actor.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories