Microsoft has detailed a post-compromise malware family called NeedyMantis that intruders have used to hold onto networks they already breached, with activity traced back to at least October 2025.
The toolkit has appeared in a small number of targeted intrusions at telecommunications firms, universities, medical nonprofits, intergovernmental organizations and government contractors. Microsoft found it while following leads from Kaspersky’s investigation into the Daemon Tools supply chain attack, where signed installers carried malicious code from April 8, 2026, until the developer shipped a clean build on May 5.
NeedyMantis arrives as three parts: a legitimate program, a malicious DLL named after a file that program loads, and an encrypted archive matching the DLL. It hides behind DLL sideloading, using real tools such as Poedit, curl, Vim and TightVNC, and has masqueraded as DLLs tied to Microsoft Office, Broadcom, Intel and NVIDIA.
Once loaded, the main component reaches a command-and-control server over HTTPS, then switches to a WebSocket that lets operators load and unload modules. Microsoft tracks the activity behind the Daemon Tools campaign as Storm-3069 and assesses it likely originates in China, though it has not linked the group to a nation-state actor. Indicators of compromise were published.
