Microsoft dissects NeedyMantis malware linked to Daemon Tools hack
Summary
Microsoft has analyzed the NeedyMantis malware, which was discovered during the investigation of a supply chain compromise involving Daemon Tools, a situation previously reported by Kaspersky. This malware is associated with threat actors from China, identified by Microsoft as Storm-3069, and is designed for long-term persistence in networks rather than immediate infection, only being deployed after initial network access has been established.
Analysis
Microsoft: Microsoft is a major technology company with a dedicated Threat Intelligence team focused on cybersecurity research and malware analysis. In September 2026, the company published a detailed dissection of the NeedyMantis malware family, tracing its origins to indicators from an earlier supply chain compromise. The analysis connects the malware to targeted operations and a specific threat actor designation. NeedyMantis: NeedyMantis is a modular post-compromise malware family engineered for stealthy persistence and follow-on activities inside compromised networks. Microsoft identified it while pivoting from research on the Daemon Tools supply chain compromise and linked it to threat actor Storm-3069. The malware has been observed in limited targeted operations against specific sectors and employs techniques such as DLL sideloading. Daemon Tools: Daemon Tools develops popular disk imaging software used for mounting virtual drives and handling ISO files on Windows systems. The application's official distribution channels were exploited in a 2026 supply chain attack where trojanized installers were served from the legitimate website. This incident provided key leads that Microsoft followed to identify and analyze the NeedyMantis malware. Malware Origin: NeedyMantis was discovered during analysis of the Daemon Tools supply chain compromise previously reported by Kaspersky. Deployment Pattern: The malware is deployed only after initial network access has been gained, focusing on long-term persistence rather than initial infection vectors. Threat Actor Context: Observed NeedyMantis activity aligns with threat actors operating from China and is tracked by Microsoft under the Storm-3069 designation.
Categories
tech
Related sources
- https://cybernoz.com/hackers-use-needymantis-to-maintain-long-term-access-in-breached-networks/
- https://therecord.media/hackers-compromise-daemon-tools-global-supply-chain-attack
- https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/
- https://techcrunch.com/2026/05/05/kaspersky-suspects-chinese-hackers-planted-a-backdoor-into-daemon-tools-in-widespread-attack/
- https://x.com/DailyDarkWeb/status/2104738301722947596
- https://www.cyberkendra.com/2026/09/needymantis-malware-microsoft-storm-3069.html
- https://arstechnica.com/security/2026/05/widely-used-daemon-tools-disk-app-backdoored-in-monthlong-supply-chain-attack/
- https://www.techspot.com/news/112318-hackers-used-daemon-tools-own-website-silently-install.html
- https://cipherssecurity.com/cve/CVE-2026-8398/
- https://x.com/aviatrixtrc/status/2104722146085757138
- https://www.kaspersky.com/about/press-releases/kaspersky-identifies-ongoing-supply-chain-attack-on-official-daemon-tools-website-distributing-backdoor-malware
- https://hacklido.com/news/hackers-use-needymantis-to-maintain-long-term-access-in-breached-networks
- https://www.helpnetsecurity.com/2026/05/06/daemon-tools-compromised-backdoors-supply-chain-attack/
- https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html