Microsoft details NeedyMantis persistence malware in targeted intrusions

Microsoft has detailed NeedyMantis, a malware family used to maintain long-term access to networks that had already been breached. The company has observed it in a small number of targeted intrusions affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations and government contractors, with activity dating back to at least October 2025.
Microsoft identified the malware while following indicators from Kaspersky's investigation of the compromise of DAEMON Tools Lite installers. The signed installers contained malicious code from April 8, 2026, until the developer replaced them with a clean version on May 5. Microsoft tracks activity associated with that campaign as Storm-3069, but says it has not observed NeedyMantis being delivered through the supply-chain attack.
DLL sideloading launches the malware
In the incidents examined by Microsoft, NeedyMantis was deployed as a three-part bundle: a legitimate application, a malicious DLL named after a DLL the application normally loads, and an encrypted archive carrying the same name as that DLL. When the application starts, it loads the malicious library through DLL sideloading.
The legitimate applications abused in this way include Poedit, curl, Vim and TightVNC. NeedyMantis has also masqueraded as DLLs associated with Microsoft Office, Broadcom, Intel and NVIDIA. In the sample Microsoft analysed in detail, the malicious library replaced WinSparkle.dll, Poedit's update component. In one intrusion, an operator already inside the victim environment used Impacket to copy the bundle from a network share and execute it on a target device.
After loading, the DLL extracts a subsequent stage from the encrypted archive. That stage decodes the main component, which connects to a command-and-control server through HTTPS and then switches to WebSocket communications. Operators can use that connection to load and unload additional modules and pass data to them. Microsoft has not confirmed the functions of those modules.
Attribution remains unresolved
An older NeedyMantis version seen in October 2025 contained a persistence module using Windows services. Microsoft did not describe how the newer sample retains its presence on a device. It also cautioned that initial access may differ between intrusions, so the malware's deployment method should not be treated as evidence of a single entry route.
Storm-3069 is a temporary Microsoft designation for a developing activity cluster. Microsoft says the group is one NeedyMantis user, while other observations of the malware indicate that multiple groups may use it. The company assesses that Storm-3069 activity appears to originate in China, but has not linked it to a Chinese nation-state actor or established that all NeedyMantis operations belong to one actor.
Google Threat Intelligence Group tracks the actor behind the DAEMON Tools campaign as UNC6863, and Mandiant described UNC6863 in June as a suspected China-nexus actor that used the compromise to deploy malware. Microsoft has not determined whether UNC6863 and Storm-3069 are the same group. Kaspersky found Chinese-language text in malware from the DAEMON Tools incident, but did not attribute that activity to a particular group.
Detection requires careful validation
Microsoft published hashes, file paths, a command-and-control domain and hunting queries for Defender XDR and Microsoft Sentinel. Its detections include TrojanDropper:Win64/NeedyMantis and Behavior:Win64/NeedyMantis. The published C2 domain is corp.tripswithengine[.]com on port 443, and the communications DLL uses the hard-coded user agent firefox/21.0.
The vendor warns that a hit on the Poedit path alone does not establish an infection: WinSparkle.dll is a legitimate Poedit component and should be compared with the published hash. Its hunting queries look back only seven days, so unchanged searches will not locate historical events from the October 2025 or May 2026 observations.
Organizations can check outbound traffic for connections to the listed domain independently of Defender and can use Microsoft's indicators to scope investigations. Microsoft also recommends cloud-delivered protection, block at first sight, EDR in block mode, network protection, automatic attack disruption and specified attack surface reduction rules. For businesses, the immediate implication is to validate suspicious sideloaded DLLs with the published hashes and extend hunt windows before treating a clean seven-day query as evidence that no prior compromise occurred.

