supply-chainvendorNewsThe Broadside1 min read

Microsoft IDs NeedyMantis malware in DAEMON Tools supply chain campaign

The modular post-compromise framework has hit government contractors, universities, and medical nonprofits, and Microsoft can't rule out multiple operators using the same tooling.


TL;DR

Microsoft Threat Intelligence has identified NeedyMantis, a modular post-compromise malware family deployed in targeted intrusions against telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. The malware, active since at least October 2025, was discovered during follow-on analysis of the DAEMON Tools supply chain compromise first reported by Kaspersky. Microsoft associates observed activity with threat actors operating from China but hasn't attributed it to a specific nation-state actor or confirmed whether all deployments trace to the same operator.

Microsoft's disclosure of NeedyMantis is the kind of threat-intelligence write-up that repays a close read, not because it drops attribution, but because it doesn't. Microsoft associates the activity with China-based operators but stops short of naming a state actor, and it explicitly leaves open the possibility that the malware is in the hands of more than one group. That restraint is itself a signal.

The malware was discovered through pivoting on indicators from the DAEMON Tools supply chain compromise, which Kaspersky had previously investigated. Microsoft designates the operator behind that campaign as Storm-3069, but it has also seen NeedyMantis in intrusions beyond Storm-3069's activity. So the tooling may be shared, borrowed, or independently fielded by multiple sets of hands. For defenders, that means hunting on IOCs alone is a starting point, not a boundary.

Architecturally, NeedyMantis is built for long-haul access: multiple loaders, custom encrypted archives, a bespoke executable format, and a modular design that lets operators bolt on new capabilities. It lands after initial access is already established, making it a persistence and follow-on platform rather than a breach tool. Victim organizations include government contractors, which puts segments of the federal supply chain in the targeting profile.

Microsoft has published IOCs, Defender detections, and hunting queries alongside the analysis. Organizations running those queries against their environments should be aware that the malware's custom file format and loader chain mean standard detection surfaces may miss it if telemetry isn't broad enough.


Published ·Deep Fathom