Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already compromised, Microsoft said in a technical analysis.
See also: Hackers use Chrome-Windows zero-days to develop CLEANGULP

The malware has been observed in a small number of targeted attacks on telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use dates back to at least October 2025.
Microsoft discovered NeedyMantis while monitoring indicators from Kaspersky into the DAEMON Tools supply chain attack. In this attack, the official, signed installers for the DAEMON Tools Lite disk imaging program contained malicious code as of April 8, 2026. The developer replaced them with a clean version on May 5.
Microsoft is tracking activity associated with this attack as Storm-3069. It says Storm-3069 is a group using NeedyMantis, although it has not seen the malware itself spread through a supply chain attack. Defenders can monitor their networks using the file hashes, domains, file paths, and search queries published by Microsoft.
In the cases Microsoft examined, NeedyMantis arrived as a three-part package: a copy of a legitimate program, a malicious DLL named like a file that loads the program, and an encrypted file with the same name as the DLL. When the program is launched, it loads the malicious DLL, a process known as DLL sideloading.
Legitimate programs used in this way include the translation tool Poedit, curl, the text editor Vim, and the remote access tool TightVNC. The malware has also been presented as DLL files from Microsoft Office, Broadcom, Intel, and NVIDIA.
In one attack, an operator already inside the network used the Impacket toolkit to copy the packet from a network share and execute it on a target. The way attackers initially gain access to a network can vary from one attack to another.
See also: Google Pixel: Hackers exploit critical vulnerability in cellular modem

Once loaded, the DLL unzips the next stage from the encrypted file and executes it. This stage decodes the main component of the malware, which connects to a command and control (C2) server over HTTPS and then switches to a WebSocket connection. Through this connection, operators can load and unload additional modules and send data to them. Microsoft has not confirmed what these modules do.
An earlier version, observed in October 2025, included a persistence module that uses Windows services. Microsoft did not describe how the newer version it analyzed persists on a machine.
Storm-3069 is a temporary name. Microsoft gives “Storm” names to new or developing groups until it is sure who is behind them or where they come from.
Microsoft has also seen NeedyMantis outside of Storm-3069's activity in the DAEMON Tools campaign and says more than one group may be using the malware. It has not determined whether all the activity comes from a single perpetrator, nor has it explained what connects Storm-3069 to NeedyMantis.
Storm-3069 activity appears to originate in China, according to Microsoft’s assessment, but the company has not linked the group to a Chinese state actor. All of the NeedyMantis activity Microsoft has seen so far fits the pattern of groups it associates with China, including targets aligned with Chinese interests and the use of the malware only against a select few organizations.
When Kaspersky uncovered the DAEMON Tools attack in May, it found Chinese-language text in the malware but did not attribute it to any specific group.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Hackers target European officials via messaging apps

The Google Threat Intelligence Group is tracking the perpetrator behind the DAEMON Tools campaign as UNC6863. In June, Mandiant described UNC6863 as “a suspected actor with connections to China” who used the DAEMON Tools breach to develop malware. It is unclear whether UNC6863 and Storm-3069 belong to the same group.
