Microsoft has detailed NeedyMantis, modular malware that attackers deploy after gaining access, which it has seen in a small number of targeted intrusions at telecommunications firms, universities, medical nonprofits, intergovernmental bodies, and government contractors.
Microsoft published its analysis of the malware’s packaging, loaders, and modular design on Sept. 28, 2026.
Microsoft said the malware usually arrives once attackers are already inside a network, which indicates it is used to hold long-term access and support later activity. Its activity dates back to at least October 2025.
Who Is Behind NeedyMantis
Microsoft has observed at least one threat actor using the malware, a group it tracks as Storm-3069, its designation for activity tied to a previously reported supply-chain compromise of DAEMON Tools. Microsoft assessed the activity originated from China, but has not attributed Storm-3069 to a Chinese nation-state actor.
The company said NeedyMantis’ activity has so far aligned with China-based actors in two respects: targeting that fits Chinese interests and a selective approach to deployment.
Microsoft found the malware while following up on indicators from the aforementioned DAEMON Tools compromise, but treats the two as separate campaigns.
Storm-3069 has been linked to supply-chain attacks, yet Microsoft has not seen NeedyMantis itself spread that way. It said a supply-chain compromise remains one possible way an attacker could gain the access needed to deploy it.
How NeedyMantis Loads and Hides
NeedyMantis ships alongside legitimate programs, which load its malicious Dynamic-Link Library (DLL) in place of a genuine one, a technique known as DLL sideloading.
Microsoft has seen it packaged with open-source tools including the Poedit translation program, curl, Vim, and TightVNC, and posing as DLL components from Microsoft Office, Broadcom, Intel, and NVIDIA.
In one intrusion, an operator used the Impacket toolkit during hands-on-keyboard activity to copy the bundle from a network share and run it on a target device.
The malware keeps its components in custom encrypted archives and a stripped-down custom executable format, while its loaders obfuscate strings and values, and include anti-debugging checks.
Once running, it contacts its Command-and-Control (C2) server over HTTPS before switching to a WebSockets connection that carries a custom protocol, compressed and optionally encrypted with RC4.
What Microsoft Has Not Confirmed
The main component has only a small number of commands, which let operators load and unload modules and pass data to them.
An older build shipped with a module that kept the malware running as a Windows service, but Microsoft said it has not confirmed what the modules loaded through those commands can do.
Microsoft said, however, that the victim profile, together with the malware’s limited observed deployment, suggests NeedyMantis is used selectively rather than broadly.
Microsoft has also seen NeedyMantis outside Storm-3069’s DAEMON Tools campaign, which it said indicates more than one operator may be using the malware. It has not determined whether the malware is available to multiple actors.