Microsoft disclosed a sophisticated malware family called NeedyMantis that attackers are using to maintain long-term access in networks they have already breached. The malware has appeared in a small number of targeted intrusions against telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors since at least October 2025.
Microsoft discovered NeedyMantis while investigating the DAEMON Tools supply chain attack that occurred in April 2026. That attack saw attackers distribute malicious code through signed installers of the DAEMON Tools Lite disk imaging software. Microsoft tracks the activity associated with that campaign as Storm-3069, a temporary designation for groups under investigation.
Unlike typical malware that serves as an initial access point, NeedyMantis is deployed only after attackers have already established a foothold inside a network. The malware operates through a sophisticated multi-stage architecture consisting of a first-stage loader, encrypted custom archives with variable encryption keys, a second-stage loader, a main component, command-and-control communications, and additional downloadable modules. This layered design complicates both static and dynamic analysis while extending functionality through modular plugins.
The malware employs multiple anti-analysis techniques to hinder detection and examination by security software. These include DLL sideloading, a technique where legitimate applications like Poedit, curl, Vim, and TightVNC are tricked into loading malicious libraries bearing the names of expected system files.
| Threat actor category | Origin/Type | Family name |
|---|---|---|
| Nation-state | Australia Canada China Germany India Iran Israel New Zealand North Korea Lebanon Pakistan Palestinian Authority Russia Singapore South Korea Spain Syria Türkiye Ukraine United Arab Emirates United Kingdom United States Vietnam |
Waterspout Freeze Typhoon Gale Monsoon Sandstorm Heatwave Swell Sleet Rain Vortex Lightning Blizzard Squall Hail Derecho Haze Dust Frost Gust Fog Tornado Cyclone |
| Financially motivated | Financially motivated | Tempest |
| Private sector offensive actors | PSOAs | Tsunami |
| Influence operations | Influence operations | Flood |
| Groups in development | Groups in development | Storm |
The malware also impersonates DLL files from Microsoft Office, Broadcom, Intel, and NVIDIA, lending legitimacy to infection attempts. In one examined case, the malicious code replaced WinSparkle.dll, the update component that Poedit uses. Additional components have been observed masquerading as legitimate system libraries including dnsapi.dll for configuration storage and ws2_32.dll for WebSocket-based command-and-control communications.
Once loaded, the DLL unpacks the next execution stage from custom encrypted archives whose offsets, XOR keys, compression methods, and filenames change between samples, complicating automated detection.
That stage decodes the malware’s main component, which connects to a command-and-control server over HTTPS before switching to a WebSocket connection. Through this channel, operators can load and unload modules and send data to them, though Microsoft has not confirmed the modules’ specific functions.
In one intrusion, an operator already inside the network used the Impacket toolkit to distribute the malware bundle from a network share and execute it on target machines. How attackers initially compromise networks varies by intrusion.
The discovery occurs amid a broader wave of telecom targeting, with February 2026 seeing Chinese actors breach more than 50 telecommunications and government agencies across 42 countries, according to CybelAngel’s analysis.
Microsoft assesses that Storm-3069’s activity appears to originate in China, though it has not attributed the group to a specific nation-state actor. However, Microsoft identified additional NeedyMantis activity beyond Storm-3069’s operations, suggesting the malware may be used by multiple operators.
Google’s Threat Intelligence Group tracks DAEMON Tools campaign activity as UNC6863, described as a suspected China-nexus actor. It remains unclear whether UNC6863 and Storm-3069 represent the same group.
Microsoft Defender detects the malware as TrojanDropper:Win64/NeedyMantis and Behavior:Win64/NeedyMantis. The company published indicators of compromise including file hashes, command-and-control domains, specific file paths, and hunting queries for both Defender XDR and Microsoft Sentinel.
They also recommend enabling cloud-delivered protection, attack surface reduction rules, and monitoring for connections to identified command-and-control infrastructure.

