Microsoft Analyzes NeedyMantis Malware: Cybersecurity Threat Breakdown
Microsoft identifies NeedyMantis malware framework linked to China-based threat actors targeting telecom and government entities.
Overview of NeedyMantis
Microsoft has analyzed a malware framework associated with a China-based threat actor targeting telecommunications and governmental organizations. The framework, identified as NeedyMantis, was uncovered during an investigation into indicators of compromise linked to the May 2026 Daemon Tools supply chain attack. This incident involved the distribution of compromised Daemon Tools software versions through the official website, resulting in thousands of infections. A backdoor was deployed on approximately a dozen systems, affecting entities in Belarus, Russia, and Thailand, including government agencies, scientific institutions, manufacturing firms, and retail organizations. A detailed report from Microsoft outlines the modular post-compromise malware used by the threat actor in targeted operations against universities, government contractors, telecom providers, medical non-profits, and intergovernmental bodies.
Targeted Organizations
The malware affected entities in Belarus, Russia, and Thailand, including government agencies, scientific institutions, manufacturing firms, and retail organizations. The report also mentions targeted operations against universities, government contractors, telecom providers, medical non-profits, and intergovernmental bodies.
Malware Timeline
The malware has been active since at least October 2025, though its association with Chinese-based threat actors remains unconfirmed. The group responsible for the Daemon Tools attack, tracked as Storm-3069, has not been definitively tied to a Chinese nation-state entity.
Infection Chain and Components
The infection chain begins with a first-stage loader bundled with legitimate software, leveraging DLL sideloading to execute the initial payload. This loader extracts and runs a second-stage component, which then deploys the main malware. The file archive includes legitimate system files, a second-stage loader, malware configuration data, a WebSockets-based communication DLL, and shellcode for loading module DLLs and resolving exports. In one observed case, attackers used the Impacket toolkit to copy legitimate software, malicious DLLs, and the file archive from a network share, executing them on a compromised device after establishing initial access. The second-stage loader decodes and decompresses embedded data, generating a minimized PE file in a custom executable format.
First-Stage Loader
The first-stage loader is bundled with legitimate software and uses DLL sideloading to execute the initial payload.
Second-Stage Loader
The second-stage loader extracts and runs the main malware, then decodes and decompresses embedded data to generate a minimized PE file in a custom executable format.
Modular Architecture and Capabilities
NeedyMantis employs a modular architecture featuring multiple loaders, custom encrypted file archives, and executable formats. Its components are written in C++ and utilize x64 shellcode to evade detection and expand functionality. The primary NeedyMantis component manages command-and-control (C&C) communication via 10 dedicated functions, enabling WebSockets connections to exfiltrate system and user data. It can also load or unload modules, dispatch data to them, and modify operational flags based on received commands. Microsoft notes that while NeedyMantis demonstrates extensibility through additional modules, the capabilities of these components remain unverified. The malware’s design emphasizes stealth and adaptability, with its modular structure allowing for dynamic updates and expanded attack vectors.
Communication and Control
The primary NeedyMantis component manages C&C communication via 10 dedicated functions, enabling WebSockets connections to exfiltrate data and load/unload modules.
Recommendations for Organizations
Microsoft advises organizations to implement strict software validation protocols, limit unnecessary network shares, and conduct regular threat hunting to detect potential indicators of compromise. The findings reinforce the need for continuous monitoring of privileged access and the adoption of advanced detection mechanisms to counter evolving malware frameworks.
Key Recommendations
Implement strict software validation, limit network shares, conduct regular threat hunting, monitor privileged access, and adopt advanced detection mechanisms.
