Skip to main content
Emerging ThreatsMalware & Ransomware

Microsoft Exposes NeedyMantis Malware Used in Long-Term Network Breaches

Technicians work in a network operations center with industrial equipment and computers in the foreground.

"The malware has been seen in a small number of targeted intrusions," Microsoft wrote, describing NeedyMantis as a lightweight but persistent tool attackers use to maintain long-term access to networks they already control.

How NeedyMantis runs

Microsoft's technical analysis shows NeedyMantis typically arrives as a three-piece bundle: a legitimate program, a malicious DLL named for a file the program expects to load, and an encrypted archive that carries the next-stage payload. The delivery method is classic DLL sideloading: when the legitimate program starts, it loads the malicious DLL, which unpacks and runs the encrypted archive. That archive decodes the malware's main component, which connects to a command-and-control server over HTTPS and then upgrades to a WebSocket connection.

Through the WebSocket channel, operators can load and unload additional modules and pass data to them; Microsoft has not confirmed what those modules do. An older sample from October 2025 included a persistence module that used Windows services. Microsoft did not describe how the newer version it analyzed maintains persistence.

Targets observed: telecommunications organizations, universities, medical nonprofits

Microsoft found NeedyMantis in a limited set of targeted intrusions across sectors. The company lists telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors among observed targets. The activity Microsoft followed tied back to October 2025 and continued into at least May 2026.

In one intrusion described by Microsoft, an operator already inside a network used the Impacket toolkit to copy the sideload bundle from a network share and execute it on a target machine. Microsoft noted that initial access vectors may vary across intrusions.

Attribution: Storm-3069, UNC6863, and Chinese-language indicators

Microsoft tracks the activity tied to the DAEMON Tools compromise as Storm-3069 and says Storm-3069 is one group that has used NeedyMantis. The company also cautioned that it has seen NeedyMantis outside Storm-3069 activity and that more than one group may be using the malware. Microsoft has not determined whether all NeedyMantis activity comes from a single actor, nor has it explained the specific link between Storm-3069 and the malware.

Microsoft assesses Storm-3069's activity appears to originate in China but has not tied the group to a Chinese nation-state actor. Kaspersky, which disclosed the DAEMON Tools supply chain attack in May, found Chinese-language text in the malware but did not attribute it to any particular group. Google Threat Intelligence Group tracks the actor behind the DAEMON Tools campaign as UNC6863, and Mandiant in June described UNC6863 as "a suspected China-nexus actor" that used the DAEMON Tools compromise to deploy malware. Microsoft said it is unclear whether UNC6863 and Storm-3069 are the same entity.

Indicators and detection: hashes, C2 domain, file paths, and Defender guidance

Microsoft published concrete indicators of compromise defenders can use to hunt for NeedyMantis. Notable SHA-256 hashes include:

  • e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e — WinSparkle.dll loader, first seen May 21, 2026
  • 9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef — encrypted archive named WinSparkle, first seen May 23, 2026
  • c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77 — encrypted archive named libcurl, older version, first seen October 3, 2025

Microsoft also listed the C2 domain corp.tripswithengine[.]com (port 443) and a hard-coded user agent value: firefox/21.0. Typical file paths abused by the malicious DLLs include program locations used by Poedit, curl, Vim, TightVNC, and folders masquerading as parts of Microsoft Office, Broadcom, Intel, and NVIDIA components — for example, %ProgramFiles%\Poedit\WinSparkle.dll and %ProgramData%\USOShared\libcurl.dll.

Microsoft Defender Antivirus labels the malware as TrojanDropper:Win64/NeedyMantis and Behavior:Win64/NeedyMantis. The company published hunting queries for Defender XDR and Microsoft Sentinel that look for the listed paths, the C2 domain, and the user agent; each query is limited to a seven-day lookback. Microsoft warned that a hit on the Poedit path alone does not prove infection because WinSparkle.dll is also a legitimate Poedit component — handlers should compare any found file to Microsoft's published hashes.

Microsoft's recommended Defender settings include cloud-delivered protection, block at first sight, EDR in block mode, network protection, automatic attack disruption, and two attack surface reduction rules. The company also advised checking outbound traffic for connections to the C2 domain, noting that this step does not require Defender tools.

What this means for technologists, procurement leaders, and end users

  • Technologists and security teams: Use Microsoft's hashes, paths, C2 domain, and user agent in hunting routines; verify suspicious DLLs against the published hashes and run the Defender XDR and Sentinel queries with an appropriate time window because the default seven-day lookback will miss earlier events.
  • Procurement and software maintainers: Note the DAEMON Tools incident timeline — official installers with malicious code were present from April 8, 2026, until the developer replaced them with a clean version on May 5, 2026 — and follow vendor guidance for compromised installers if applicable.
  • End users of DAEMON Tools: The DAEMON Tools developer advised that anyone who downloaded or installed DAEMON Tools Lite 12.5.1 during the affected period should uninstall it, run a full system scan, and download version 12.6 from the official website.

Microsoft has tied NeedyMantis activity to a handful of targeted intrusions, published specific indicators, and set out defensive configurations — but it has not said whether NeedyMantis is still in active use nor resolved whether the activity represents a single actor. The practical work for defenders is concrete: hunt for the listed hashes, check outbound traffic for corp.tripswithengine[.]com, and treat suspicious DLLs with caution while comparing them to the published values.

Source: The Hacker News — Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks