
Microsoft Details NeedyMantis Malware Used to Keep Long-Term Access in Breached Networks
Microsoft has published a technical analysis of NeedyMantis, a malware family used to hold long-term access in networks that were already breached. Its use dates back to at least October 2025.
Microsoft has published a technical analysis of NeedyMantis, a malware family that hackers use to keep long-term access to networks they had already breached. It appeared in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits and government contractors, with use dating back to at least October 2025.
Microsoft found the malware while following up on indicators from Kaspersky's investigation into the supply chain attack on DAEMON Tools. Signed installers for DAEMON Tools Lite carried malicious code from April 8, 2026, and were replaced with a clean version on May 5. Microsoft tracks the activity tied to that attack as Storm-3069.
How NeedyMantis runs
NeedyMantis arrived as three parts: a copy of a legitimate program, a malicious DLL named after a file that program loads, and an encrypted archive with the DLL's name. When the program starts it loads the malicious DLL, a technique called DLL sideloading.
The legitimate programs used this way include Poedit, curl, Vim and TightVNC, and the malware has also posed as DLL files from Microsoft Office, Broadcom, Intel and NVIDIA. In the sample analysed in detail it replaced WinSparkle.dll, the update component Poedit uses.
Once loaded, the DLL unpacks the next stage from the encrypted archive and that stage decodes the main component, which connects to a command-and-control (C2) server over HTTPS and then switches to a WebSocket connection, where operators can load and unload extra modules.
Who is behind it
Storm-3069 is a temporary name, which Microsoft gives to new or developing groups until it is confident about who is behind them. The company has also seen NeedyMantis outside that group's activity and says more than one group may be using it. It assesses the activity originates in China but has not tied it to a Chinese nation-state actor.
Google Threat Intelligence Group tracks the actor behind the DAEMON Tools campaign as UNC6863, which Mandiant described in June as a suspected China-nexus actor.
How to check for NeedyMantis
Microsoft published three SHA-256 hashes, the C2 domain corp.tripswithengine[.]com on port 443 and the user agent firefox/21.0 hard-coded in the malware's communications DLL. One path used by the malicious DLLs is %ProgramFiles%\Poedit\WinSparkle.dll.
Microsoft Defender Antivirus detects the malware as TrojanDropper:Win64/NeedyMantis and Behavior:Win64/NeedyMantis. A hit on the Poedit path alone does not prove an infection, because WinSparkle.dll is also a normal part of Poedit, so any file found there should be compared with the published hash. Microsoft also advises checking outbound traffic for connections to the C2 domain.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.