Microsoft has analyzed a malware framework used by a China-based threat actor in attacks against telecommunications and governmental organizations.
Dubbed NeedyMantis, the framework was discovered during the follow-on analysis of indicators of compromise (IoCs) associated with the May 2026 Daemon Tools supply chain attack.
Thousands of computers were infected through poisoned Daemon Tools iterations distributed through the official website, and a backdoor was deployed on roughly a dozen of them. Government, scientific, manufacturing, and retail organizations in Belarus, Russia, and Thailand were hit.
In a fresh report, Microsoft provides a detailed analysis of NeedyMantis, the modular post-compromise malware the Daemon Tools hackers used in targeted attacks against universities, government contractors, and telecoms, as well as medical non-profit and intergovernmental organizations.
“Based on observed activity, NeedyMantis is typically deployed after a threat actor has already established access to a target environment, indicating that the malware is used to maintain long-term access and support follow-on operations,” Microsoft notes.
NeedyMantis has been used in attacks since at least October 2025, likely by more threat actors based in China. According to Microsoft, the hacking group behind the Daemon Tools attack, tracked as Storm-3069, has not been attributed to a Chinese nation-state actor.
Used only in targeted attacks, the malware framework has a modular architecture consisting of multiple loaders, custom encrypted file archives and executable file formats, and modular components in C++ and x64 shellcode, designed to evade detection and expand capabilities.
The NeedyMantis infection chain starts with a first-stage loader and a file archive packaged alongside legitimate software. It abuses DLL sideloading to execute the loader, which in turn extracts and runs a second-stage loader to execute the main malware component.
The file archive contains multiple legitimate software and system components, a second-stage loader, the malware configuration, a WebSockets-based communication DLL, and shellcode to load module DLLs and resolve exports.
“In one observed incident, an operator used the Impacket toolkit during hands-on-keyboard activity to copy the legitimate software, malicious DLL, and file archive from a network share and execute it on a targeted device. This activity occurred after the actor had already obtained access to the environment,” Microsoft says.
The second-stage loader extracts embedded data and decodes and decompresses it. The resulting data is a minimized version of a PE file, in the form of a DLL formatted using a custom executable file format.
NeedyMantis’ main component orchestrates command-and-control (C&C) communication through 10 functions designed to initiate and maintain a WebSockets connection. It also sends system and user information to the C&C, and, based on received commands, can load or unload modules, dispatch data to modules, and turn off flags.
“The main component’s load, unload, and data dispatch commands show that NeedyMantis can extend its functionality through additional modules, but the capabilities of those modules remain unconfirmed,” Microsoft notes.
Related: Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
Related: Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability
Related: New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
Related: Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer

