Microsoft Threat Intelligence said on September 28, 2026 that it has identified NeedyMantis, a modular post-compromise malware family used in a limited number of targeted operations against telecommunications organizations, universities, medical nonprofits, intergovernmental organizations and government contractors. The company said it found the family while pivoting from indicators tied to the DAEMON Tools supply chain compromise.
Who Microsoft says is using it
Microsoft said it has observed at least one threat actor using NeedyMantis: Storm-3069, its designator for activity associated with the DAEMON Tools supply chain compromise. The company said it assesses that the activity originates from China but has not attributed Storm-3069 to a Chinese nation-state actor.
Additional NeedyMantis activity beyond the DAEMON Tools campaign suggests the malware might be used by more than one operator, according to Microsoft, which said observed activity has so far aligned with activity it associates with threat actors operating from China, including targeting that aligns with Chinese interests and selective deployment.
Microsoft said NeedyMantis activity dates back to at least October 2025, and that it has not determined whether all observed activity is attributable to the same operator. It credited Kaspersky's earlier reporting on the DAEMON Tools campaign as the starting point for its analysis.
How the malware is delivered
NeedyMantis is composed of multiple components written in C++ and x64 shellcode, Microsoft said, starting with a first-stage loader and a file archive. The loader masquerades as a required DLL and is loaded through DLL sideloading alongside legitimate software.
Abused open-source software named in the report includes Poedit, curl, Vim and TightVNC. Microsoft said it has also seen NeedyMantis masquerading as Microsoft Office, Broadcom, Intel and NVIDIA DLL components, using paths such as %ProgramFiles%PoeditWinSparkle.dll and %ProgramData%Inteljli.dll.
In one incident, Microsoft said an operator used the Impacket toolkit during hands-on-keyboard activity to copy the legitimate software, malicious DLL and file archive from a network share and execute them on a targeted device. Microsoft said it has not observed NeedyMantis itself being distributed through a supply chain compromise.
Technical details
According to Microsoft, the first-stage loader uses obfuscated stack strings, obfuscated constants and two anti-debugger methods based on ProcessDebugFlags and ThreadHideFromDebugger. Its only job is to extract a second-stage loader from an encrypted, compressed custom archive whose offsets and XOR keys change between samples.
The analyzed second stage, named encryptbase64.ps1 despite its PowerShell extension, contains x64 shellcode and resolves Windows APIs using a rotate-right hashing algorithm. It decodes an embedded DLL stored in a custom executable format that Microsoft describes as a minimized version of a PE file.
The main component orchestrates command-and-control traffic and loads additional modules. Microsoft said the configuration, stored in a file named dnsapi.dll, listed C2 host corp.tripswithengine[.]com on port 443 with URI /library/zip/. A communications DLL exporting SystemInfo maintains a WebSockets connection using WinINet APIs and a hard-coded user-agent of firefox/21.0; a second version uses Libwebsockets instead.
The initial beacon is an HTTPS GET whose Set-Cookie header carries Base64-encoded, compressed system information including computer name, username, process list and files in the ProgramFiles directory. Microsoft said the main component supports commands to load, unload and dispatch data to modules, but the capabilities of those modules remain unconfirmed.
What to do
- Look for outbound connections in network egress traffic to corp.tripswithengine[.]com.
- Turn on cloud-delivered protection and block at first sight to identify and block new and unknown malware variants.
- Run endpoint detection and response in block mode so Microsoft Defender for Endpoint can block malicious artifacts even when another antivirus misses them.
- Enable network protection in Microsoft Defender for Endpoint and configure automatic attack disruption in Microsoft Defender XDR.
- Turn on attack surface reduction rules that block executable files unless they meet prevalence, age or trusted-list criteria, and block execution of potentially obfuscated scripts.
- Run the advanced hunting queries Microsoft published for Defender XDR and Sentinel to check for sideloaded DLL paths, the C2 domain and the Firefox/21.0 user-agent.
- Check the published SHA-256 hashes for the WinSparkle loader and the WinSparkle and libcurl custom archives against your environment.
Key facts and where they come from
- Microsoft identified NeedyMantis as a modular post-compromise malware family in limited targeted operations.
Microsoft Threat Intelligence has identified NeedyMantis, a modular post-compromise malware family observed in a limited number of targeted operations
- Observed victims include telecoms, universities, medical nonprofits, intergovernmental organizations and government contractors.
affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors
- Activity dates back to at least October 2025 and was found via DAEMON Tools research.
NeedyMantis activity dates back to at least October 2025.
- Microsoft has observed Storm-3069 using the malware but has not attributed it to a Chinese nation-state actor.
While Microsoft assesses the activity originates from China, it has not attributed Storm-3069 to a Chinese nation-state actor.
- The first-stage loader is delivered by DLL sideloading alongside legitimate software.
the first-stage loader–masquerading as a required DLL—being loaded through DLL sideloading
- Configuration named C2 host corp.tripswithengine[.]com on port 443.
0x128: C2 port (443)
0x12c: C2 host (corp.tripswithengine[.]com) - The communications DLL uses WinINet APIs for WebSockets with a hard-coded user-agent.
The library uses WinINet APIs for WebSockets. It also has a hard-coded user-agent of firefox/21.0.
- Module capabilities are not confirmed.
NeedyMantis can extend its functionality through additional modules, but the capabilities of those modules remain unconfirmed
- An operator used Impacket during hands-on-keyboard activity to stage the components.
an operator used the Impacket toolkit during hands-on-keyboard activity to copy the legitimate software, malicious DLL, and file archive from a network share
