Microsoft Warns of NeedyMantis Malware Used for Long-Term Network Access

Microsoft has detailed a malware family called NeedyMantis that has been used to maintain long-term access to already compromised networks in a small number of targeted attacks.

The malware has been observed targeting organizations in the telecommunications, education, healthcare, intergovernmental, and government contractor sectors. Microsoft said the activity dates back to at least October 2025.

Microsoft identified NeedyMantis while investigating indicators connected to the DAEMON Tools Lite supply chain compromise. Microsoft tracks activity associated with that incident as Storm-3069, although it has not observed NeedyMantis being distributed through the DAEMON Tools supply chain itself.

NeedyMantis Uses DLL Sideloading

In the intrusions analyzed by Microsoft, NeedyMantis was delivered as a three-part bundle containing:

  1. A legitimate executable
  2. A malicious DLL using the name of a legitimate DLL loaded by that executable
  3. An encrypted archive using the same name as the malicious DLL

When the legitimate application launches, it loads the malicious DLL through DLL sideloading.

Programs abused as legitimate loaders have included:

  • Poedit
  • curl
  • Vim
  • TightVNC

The malware has also used DLL names associated with products from Microsoft Office, Broadcom, Intel, and NVIDIA.

In one analyzed sample, the attackers replaced WinSparkle.dll, an update component used by Poedit.

Post-Compromise Deployment

Microsoft observed NeedyMantis being deployed by attackers who already had access to the target network.

In one intrusion, an operator used the Impacket toolkit to copy the malware bundle from a network share and execute it on another system.

This indicates that the malware functions primarily as a post-compromise persistence and access tool, rather than necessarily being responsible for the initial breach.

Once the malicious DLL is loaded, it extracts the next stage from the encrypted archive and executes it.

The next stage then decodes the malware's primary component, which communicates with its command-and-control infrastructure over HTTPS before switching to a WebSocket connection.

Modular Architecture

The main NeedyMantis component supports a modular architecture.

Through the WebSocket connection, operators can load and unload additional modules and exchange data with those modules.

Microsoft has not confirmed the exact capabilities of the additional modules.

An older version of NeedyMantis identified in October 2025 contained a persistence module that used Windows services.

Microsoft did not disclose how the newer version maintains persistence.

Microsoft currently tracks some activity involving NeedyMantis under the temporary actor designation Storm-3069.

Microsoft said it has also observed NeedyMantis outside activity associated with the DAEMON Tools investigation, suggesting that more than one group may be using the malware.

The company has not established whether all NeedyMantis activity originates from a single threat actor or determined the exact relationship between Storm-3069 and the malware.

Microsoft assesses that Storm-3069 activity appears to originate from China, but it has not attributed the group to a Chinese nation-state actor.

The targeting patterns observed by Microsoft are consistent with activity it associates with China-linked groups, including the selection of organizations that align with Chinese strategic interests.

When the DAEMON Tools compromise was publicly disclosed, Kaspersky also identified Chinese-language content in the malware but did not attribute the campaign to a specific group.

Google Threat Intelligence tracks the actor behind the DAEMON Tools campaign as UNC6863 and has described it as a suspected China-nexus actor. It remains unclear whether UNC6863 and Storm-3069 represent the same group.

Indicators of Compromise

Microsoft published several indicators associated with NeedyMantis.

File Hashes

e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e

First-stage WinSparkle.dll loader, first observed May 21, 2026.

9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef

Encrypted archive named WinSparkle, first observed May 23, 2026.

c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77

Older encrypted archive named libcurl, first observed October 3, 2025.

Network Indicators

C2 domain:

corp.tripswithengine[.]com

The C2 server uses port 443.

Hard-coded User-Agent:

firefox/21.0

Malicious DLL Paths

Microsoft identified the following paths associated with NeedyMantis samples:

%ProgramFiles%\Poedit\WinSparkle.dll
%ProgramData%\USOShared\libcurl.dll
%ProgramData%\VIM\vim64.dll
%ProgramData%\TightVNC\VIM\vim64.dll
%ProgramData%\office\dbghelp.dll
%ProgramData%\broadcom\dbghelp.dll
%ProgramData%\Intel\jli.dll
%ProgramFiles%\modifiable\nvml.dll
%ProgramData%\ics\nvml.dll

Microsoft Defender Antivirus detects the malware as:

TrojanDropper:Win64/NeedyMantis
Behavior:Win64/NeedyMantis

Detection and Hunting

Microsoft has published hunting queries for Microsoft Defender XDR and Microsoft Sentinel.

The queries search for indicators such as:

  • Known malicious DLL paths
  • NeedyMantis C2 infrastructure
  • The firefox/21.0 User-Agent

However, Microsoft noted that the published queries look back only seven days.

Because the identified samples were first observed in October 2025 and May 2026, running the queries without modification may not identify historical activity.

Security teams should therefore extend the search period where historical telemetry is available.

A match for the Poedit path alone does not confirm an infection because WinSparkle.dll is also a legitimate component of Poedit. File hashes and additional indicators should be used to validate suspicious findings.

Microsoft recommends enabling security controls including:

  • Cloud-delivered protection
  • Block at first sight
  • Endpoint Detection and Response in block mode
  • Network protection
  • Automatic attack disruption
  • Recommended attack surface reduction rules

Organizations should also monitor outbound traffic from potentially affected systems for connections to the identified C2 infrastructure.

DAEMON Tools Supply Chain Incident

Microsoft emphasized that it has not observed NeedyMantis being delivered through the compromised DAEMON Tools installers.

The DAEMON Tools Lite supply chain incident involved legitimate signed installers that were modified to contain malicious code between April 8 and May 5, 2026.

Organizations that downloaded or installed the affected version should follow the software developer's remediation guidance, including removing the affected software, performing a full security scan, and installing a clean version from the official source.

Key Takeaway

NeedyMantis is primarily being used as a post-compromise malware family that helps attackers maintain access to already breached environments.

Its combination of DLL sideloading, encrypted payloads, modular architecture, HTTPS and WebSocket communications, and multiple legitimate software loaders makes it important for organizations to hunt beyond the initial infection point.

Security teams should investigate the published file hashes, DLL paths, C2 indicators, and historical network telemetry, particularly in organizations where the targeted software and sectors overlap with Microsoft's observations.