Hackers Deploy NeedyMantis Malware: Understanding Its Stealthy Persistence in Breached Networks

4

Hackers Deploy NeedyMantis Malware to Quietly Burrow Into Breached Networks

Microsoft has identified a malware family called NeedyMantis being used to maintain long-term access inside breached networks across telecommunications firms, universities, medical nonprofits, and government contractors since at least October 2025. The campaign has drawn urgent attention from defenders precisely because of how little noise it makes — this is not opportunistic intrusion, but calculated, sustained infiltration.

The discovery raises urgent concerns for organizations that may already be compromised without knowing it. NeedyMantis is not a smash-and-grab tool — it is engineered for persistence, operating quietly inside networks while giving attackers ongoing remote control. Microsoft's findings suggest that multiple threat groups may be using the malware, and that its operators show a pattern consistent with Chinese state-aligned activity, though no formal attribution to a Chinese nation-state actor has been made.

Understanding how this malware operates requires familiarity with the broader category of threats it belongs to. Advanced persistent threats and how long-dwell attackers operate provide essential context for why campaigns like NeedyMantis are so difficult to detect and contain once they take hold.


How NeedyMantis Infiltrates and Persists Inside Networks

The Three-Part Delivery Mechanism

NeedyMantis arrives as a three-part bundle: a legitimate program, a malicious DLL file named to match one the program normally loads, and an encrypted archive sharing the DLL's name. When the legitimate program launches, it unknowingly loads the malicious DLL — a technique known as DLL sideloading.

The legitimate programs exploited this way include the Poedit translation tool, curl, the Vim text editor, and the TightVNC remote access tool. The malware has also disguised its DLL files as components from Microsoft Office, Broadcom, Intel, and NVIDIA — trusted names that security teams are unlikely to flag immediately. This deliberate use of trusted software identities is central to why NeedyMantis evades detection for extended periods.

In one documented intrusion, an operator already inside the target network used the Impacket toolkit to copy the malware bundle from a network share and deploy it on a target machine. How attackers initially gain access may vary across intrusions.

How the Infection Chain Executes

Once the malicious DLL loads, it unpacks the next stage from the encrypted archive. That stage then decodes the malware's main component, which connects to a command-and-control (C2) server over HTTPS before switching to a WebSocket connection. Through that connection, operators can load and unload additional modules and transmit data. Microsoft has not yet confirmed what those modules do.

An older version of NeedyMantis detected in October 2025 included a persistence module using Windows services. Microsoft did not detail how the newer version maintains its foothold on a machine — a gap in public knowledge that defenders should treat as a reason for heightened caution rather than reassurance.

To understand the full scope of threats that use similar delivery and evasion techniques, reviewing the different types of malware and how each category operates helps security teams build a more complete detection posture.


The Threat Group Behind NeedyMantis and Its Supply Chain Connection

Storm-3069 and the DAEMON Tools Attack

Microsoft tracks the primary activity cluster using NeedyMantis as Storm-3069 — a temporary designation the company assigns to emerging or developing threat groups before formal attribution is possible. Microsoft discovered NeedyMantis while following up on indicators from Kaspersky's investigation into a supply chain attack on DAEMON Tools, the widely used disk image software.

In that attack, official and digitally signed installers for DAEMON Tools Lite carried malicious code from April 8, 2026. The developer replaced them with a clean version on May 5, 2026. Kaspersky found Chinese-language text embedded in the malware but stopped short of attributing it to a specific group. Google Threat Intelligence Group tracks the actor behind the DAEMON Tools campaign as UNC6863, and Mandiant described UNC6863 in June 2026 as "a suspected China-nexus actor" that used the compromise to deploy malware.

What Attribution Evidence Exists — and What Remains Uncertain

Microsoft says Storm-3069's activity appears to originate in China and fits patterns it associates with China-linked groups — including a narrow target set aligned with Chinese strategic interests. Whether UNC6863 and Storm-3069 belong to the same group remains unconfirmed. Importantly, Microsoft has not seen NeedyMantis itself spread through the tampered DAEMON Tools installers.

For users who downloaded DAEMON Tools Lite 12.5.1 during the affected period, the developer has advised uninstalling the software, running a full system scan, and downloading the clean version 12.6 from the official website.

Supply chain compromises of this kind are particularly damaging because they weaponize the trust users place in software they deliberately sought out and installed from official sources. Organizations that rely on third-party tools across their environment — especially remote access and productivity utilities — should treat vendor software integrity as an active security concern, not a passive assumption. For a broader understanding of how attackers exploit remote network access tools and the risks they introduce, the attack surface involved in campaigns like this becomes significantly clearer.


How Defenders Can Detect and Respond to NeedyMantis

Indicators of Compromise to Check Now

Microsoft has published a detailed set of indicators of compromise that security teams can use to search their environments. Key file hashes include:

  • SHA-256: e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e (first-stage loader WinSparkle.dll, first seen May 21, 2026)
  • SHA-256: 9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef (encrypted archive named WinSparkle, first seen May 23, 2026)
  • SHA-256: c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77 (older encrypted archive named libcurl, first seen October 3, 2025)

The known C2 domain is corp.tripswithengine[.]com on port 443. The malware uses a hard-coded user agent string of firefox/21.0 in its communications — an anomaly that network monitoring tools can flag without requiring endpoint access. No modern browser identifies itself as Firefox 21.0, making this a relatively reliable detection signal in network traffic logs.

Suspicious file paths to watch for include locations such as %ProgramFiles%\Poedit\WinSparkle.dll and %ProgramData%\USOShared\libcurl.dll among others published by Microsoft. Security teams should note that WinSparkle.dll is also a legitimate Poedit file — any file found at that path should be compared against the published malicious hash before drawing conclusions. Acting on path alone risks disrupting legitimate software.

Microsoft Defender Antivirus detects NeedyMantis as TrojanDropper:Win64/NeedyMantis and Behavior:Win64/NeedyMantis. Microsoft has also published hunting queries for Defender XDR and Microsoft Sentinel, though each query looks back only seven days — meaning organizations searching for the earliest known activity from October 2025 or May 2026 would need to adjust the query window accordingly. This is a non-trivial consideration: if NeedyMantis has been present since late 2025, a seven-day lookback will return a clean result that tells defenders very little.

Recommended Defender settings include cloud-delivered protection, block at first sight, EDR in block mode, network protection, and automatic attack disruption. Microsoft also advises monitoring outbound traffic for connections to the known C2 domain — a step that does not require Defender at all and is accessible to any organization running network monitoring tools. For additional guidance on threat hunting methodology, MITRE ATT&CK provides a structured framework for mapping adversary behavior — including DLL sideloading and C2 over WebSocket — to detection opportunities.

Prioritizing Response for At-Risk Sectors

The NeedyMantis campaign is a reminder that long-dwell-time threats remain among the hardest to detect and the most damaging to contain. The longer an attacker maintains undetected access, the deeper their understanding of the target environment becomes — and the more difficult remediation is once discovery occurs.

Security teams at organizations in the targeted sectors — telecommunications, academia, healthcare nonprofits, and government contracting — should treat this as a priority review item. Checking published file hashes against files found in suspicious paths, monitoring for the anomalous firefox/21.0 user agent, and enabling Microsoft's recommended Defender protections are concrete steps any defender can take today. Organizations that lack the internal capacity to run these checks should consider engaging an external incident response or threat hunting team with access to historical log data extending beyond the default seven-day query window.

You might also like