Microsoft dissects NeedyMantis malware linked to Daemon Tools hack

Summary

Microsoft has analyzed the NeedyMantis malware, which was discovered during the investigation of a supply chain compromise involving Daemon Tools, a situation previously reported by Kaspersky. This malware is associated with threat actors from China, identified by Microsoft as Storm-3069, and is designed for long-term persistence in networks rather than immediate infection, only being deployed after initial network access has been established.

Analysis

Microsoft: Microsoft is a major technology company with a dedicated Threat Intelligence team focused on cybersecurity research and malware analysis. In September 2026, the company published a detailed dissection of the NeedyMantis malware family, tracing its origins to indicators from an earlier supply chain compromise. The analysis connects the malware to targeted operations and a specific threat actor designation. NeedyMantis: NeedyMantis is a modular post-compromise malware family engineered for stealthy persistence and follow-on activities inside compromised networks. Microsoft identified it while pivoting from research on the Daemon Tools supply chain compromise and linked it to threat actor Storm-3069. The malware has been observed in limited targeted operations against specific sectors and employs techniques such as DLL sideloading. Daemon Tools: Daemon Tools develops popular disk imaging software used for mounting virtual drives and handling ISO files on Windows systems. The application's official distribution channels were exploited in a 2026 supply chain attack where trojanized installers were served from the legitimate website. This incident provided key leads that Microsoft followed to identify and analyze the NeedyMantis malware. Malware Origin: NeedyMantis was discovered during analysis of the Daemon Tools supply chain compromise previously reported by Kaspersky. Deployment Pattern: The malware is deployed only after initial network access has been gained, focusing on long-term persistence rather than initial infection vectors. Threat Actor Context: Observed NeedyMantis activity aligns with threat actors operating from China and is tracked by Microsoft under the Storm-3069 designation.

Categories

tech

Related sources

View Original Tweet