Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference

    September 29, 2026

    SpaceX Has More Annual Recurring Revenue than Anthropic – NextBigFuture.com

    September 29, 2026

    Webshare review | TechRadar

    September 29, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft
    Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft
    Cybersecurity

    Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft

    The Tech GuyBy The Tech GuySeptember 29, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Microsoft has analyzed a malware framework used by a China-based threat actor in attacks against telecommunications and governmental organizations.

    Advertisement

    Dubbed NeedyMantis, the framework was discovered during the follow-on analysis of indicators of compromise (IoCs) associated with the May 2026 Daemon Tools supply chain attack.

    Thousands of computers were infected through poisoned Daemon Tools iterations distributed through the official website, and a backdoor was deployed on roughly a dozen of them. Government, scientific, manufacturing, and retail organizations in Belarus, Russia, and Thailand were hit.

    In a fresh report, Microsoft provides a detailed analysis of NeedyMantis, the modular post-compromise malware the Daemon Tools hackers used in targeted attacks against universities, government contractors, and telecoms, as well as medical non-profit and intergovernmental organizations.

    “Based on observed activity, NeedyMantis is typically deployed after a threat actor has already established access to a target environment, indicating that the malware is used to maintain long-term access and support follow-on operations,” Microsoft notes.

    NeedyMantis has been used in attacks since at least October 2025, likely by more threat actors based in China. According to Microsoft, the hacking group behind the Daemon Tools attack, tracked as Storm-3069, has not been attributed to a Chinese nation-state actor.

    Advertisement. Scroll to continue reading.

    Used only in targeted attacks, the malware framework has a modular architecture consisting of multiple loaders, custom encrypted file archives and executable file formats, and modular components in C++ and x64 shellcode, designed to evade detection and expand capabilities.

    The NeedyMantis infection chain starts with a first-stage loader and a file archive packaged alongside legitimate software. It abuses DLL sideloading to execute the loader, which in turn extracts and runs a second-stage loader to execute the main malware component.

    The file archive contains multiple legitimate software and system components, a second-stage loader, the malware configuration, a WebSockets-based communication DLL, and shellcode to load module DLLs and resolve exports.

    “In one observed incident, an operator used the Impacket toolkit during hands-on-keyboard activity to copy the legitimate software, malicious DLL, and file archive from a network share and execute it on a targeted device. This activity occurred after the actor had already obtained access to the environment,” Microsoft says.

    The second-stage loader extracts embedded data and decodes and decompresses it. The resulting data is a minimized version of a PE file, in the form of a DLL formatted using a custom executable file format.

    NeedyMantis’ main component orchestrates command-and-control (C&C) communication through 10 functions designed to initiate and maintain a WebSockets connection. It also sends system and user information to the C&C, and, based on received commands, can load or unload modules, dispatch data to modules, and turn off flags.

    “The main component’s load, unload, and data dispatch commands show that NeedyMantis can extend its functionality through additional modules, but the capabilities of those modules remain unconfirmed,” Microsoft notes.

    Related: Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign

    Related: Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability

    Related: New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

    Related: Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference

    September 29, 2026

    RemoteThreat Launches With $7 Million for Offensive Operations Platform

    September 29, 2026

    Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon

    September 29, 2026

    Modulate Raises $25 Million to Advance Deepfake Detection

    September 28, 2026

    Call for Presentations Open for 2026 CISO Forum Virtual Summit

    September 28, 2026

    New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections

    September 28, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026211 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference

    September 29, 2026

    SpaceX Has More Annual Recurring Revenue than Anthropic – NextBigFuture.com

    September 29, 2026

    Webshare review | TechRadar

    September 29, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.