Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

Microsoft details NeedyMantis malware found while probing the Daemon Tools attack

Microsoft says the modular implant, active since October 2025, is deployed after attackers get in and has hit telecoms, universities and government contractors.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Microsoft says NeedyMantis malware is deployed after initial access to keep long-term access and support follow-on operations.
  • 2Microsoft found it while pivoting from research on the Daemon Tools compromise but has not tied delivery to those installers.
  • 3Targets include telecoms, universities, medical nonprofits, intergovernmental bodies and government contractors; activity dates to October 2025.

The news

Microsoft Threat Intelligence on September 28 published an analysis of NeedyMantis malware, a modular toolkit it says attackers deploy after they already have a foothold, to keep long-term access. Targets include telecoms, universities and government contractors.

Microsoft (MSFT) said it discovered the malware family while analyzing and pivoting from research tied to the supply chain compromise of Daemon Tools, a widely used disk image program. It said it has observed NeedyMantis since October 2025 against telecommunications organizations, universities, medical nonprofits, intergovernmental organizations and government contractors.

The Daemon Tools incident was first disclosed by Kaspersky in May. As reported by The Hacker News, official, signed installers for Daemon Tools Lite carried malicious code from April 8, 2026, until the developer replaced them with a clean version on May 5. Version 12.5.1 was affected, and version 12.6 is clean. SecurityWeek reported that thousands of computers were infected through the poisoned installers and that a backdoor was deployed on roughly a dozen of them.

Microsoft did not say NeedyMantis itself arrived through the tampered installers. The Hacker News reported that Microsoft has not seen the malware spread that way. Microsoft tracks the group using it as Storm-3069, a temporary name for a developing cluster. It said the activity aligns with what it associates with threat actors operating from China, but that it has not determined whether all observed activity comes from the same operator.

According to SecurityWeek, Microsoft has not attributed Storm-3069 to a Chinese nation-state actor. Google Threat Intelligence Group, part of Alphabet (GOOGL), tracks the actor behind the Daemon Tools compromise as UNC6863, The Hacker News reported, and Microsoft has not confirmed whether the two names describe the same group.

The malware relies on DLL sideloading, in which a trusted program is tricked into loading a malicious library, or DLL, placed alongside it. Microsoft said the attack chains involve legitimate software including Poedit, curl, Vim and TightVNC, with malicious files posing as components from Microsoft Office, Broadcom (AVGO), Intel (INTC) and Nvidia (NVDA). NeedyMantis then talks to its command server over WebSockets, a persistent two-way web connection, through a communications DLL that exposes 10 functions. Commands let operators load and unload modules, though Microsoft said the capabilities of those modules remain unconfirmed. It also said operators used Impacket, an open-source network toolkit, during hands-on-keyboard activity.

The numbers

NeedyMantis first observed
October 2025 (Microsoft)
Daemon Tools installer compromise window
April 8 to May 5, 2026 (The Hacker News)
Affected Daemon Tools Lite version
12.5.1; clean version 12.6
Functions exposed by the WebSockets communications DLL
10 (Microsoft)
Lookback of Microsoft's published hunting queries
7 days (The Hacker News)

Why CEOs should care

For CISOs at telecoms, universities, nonprofits and government contractors, the practical step is a hunt. Microsoft published a command-and-control domain, corp.tripswithengine[.]com, and Defender detection names TrojanDropper:Win64/NeedyMantis and Behavior:Win64/NeedyMantis. The Hacker News noted that Microsoft's hunting queries look back only seven days, so teams should widen the window to October 2025. Also look for legitimate tools such as Vim, curl or TightVNC running from unusual folders and loading unexpected DLLs, and for Daemon Tools Lite 12.5.1 installs from the April 8 to May 5 window.

Boards and CFOs should note what this tool is for. Microsoft describes NeedyMantis as post-compromise malware, so a detection means an intruder was already inside and should be handled as an incident, not a routine cleanup. Ask whether the company keeps an inventory of software staff install themselves, such as disk image utilities, and whether endpoint tools can flag DLL sideloading. Microsoft recommends running endpoint detection and response in block mode, enabling cloud-delivered protection, network protection and automatic attack disruption, and applying attack surface reduction rules.

Technology buyers should take a narrower lesson from the Daemon Tools episode: a signed installer from a vendor's official website was not safe for nearly four weeks. Ask software suppliers how they protect their build and signing pipeline, how quickly they notify customers of tampering, and how customers can verify which version they received.

The bigger picture

The case shows how tangled attribution becomes once a campaign spans a poisoned installer and later follow-on tooling. Kaspersky found the Daemon Tools compromise, Google tracks the actor as UNC6863, and Microsoft uses Storm-3069 for the group it sees deploying NeedyMantis, without saying they are one and the same. For defenders, the names matter less than the behavior: trusted, signed software used as a way in, then legitimate programs abused to hide malicious code for months.

What’s next

Microsoft said the capabilities of NeedyMantis modules remain unconfirmed, so further research may show what the implant was used to collect. Security teams in the targeted sectors should run Microsoft's indicators against historical logs, not just the last week, and watch for any vendor update that connects or separates Storm-3069 and UNC6863.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

MicrosoftNeedyMantisDaemon ToolsStorm-3069Supply chain attacks

Earlier coverage of Microsoft

All Microsoft coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.