A fake update component for the Poedit translation app gave attackers a quiet foothold on Windows machines. According to Microsoft Threat Intelligence’s new analysis of NeedyMantis, this trick is one of several used by a modular backdoor. The NeedyMantis malware has hit telecom firms, universities, medical nonprofits, intergovernmental bodies, and government contractors since at least October 2025.
At a Glance
| Malware family | NeedyMantis (modular post-compromise backdoor) |
| Threat actor | Storm-3069 confirmed as one user; other operators suspected |
| Targets | Telecom, universities, medical nonprofits, intergovernmental organizations, government contractors |
| Delivery vector | DLL sideloading through legitimate software, after initial access |
| Key capabilities | Layered loaders, encrypted custom archives, WebSockets C2, plug-in modules |
| Sources | Microsoft Threat Intelligence; Kaspersky DAEMON Tools research |
TL;DR
NeedyMantis is a backdoor that attackers install after they already have a way in. It hides behind trusted apps through DLL sideloading and talks to its server over encrypted WebSockets. Microsoft ties at least one user, Storm-3069, to the DAEMON Tools supply chain attack.
How Microsoft Found It
Microsoft spotted the malware while digging into indicators from the DAEMON Tools breach. Kaspersky first exposed that campaign in May 2026. Back then, attackers had slipped backdoors into signed DAEMON Tools installers on the vendor’s own website. Kaspersky counted several thousand infection attempts across more than 100 countries. However, only about a dozen hosts received a second-stage backdoor.
That pattern of wide reach and narrow follow-up matches what Microsoft now sees. In its words, the victim profile “suggests NeedyMantis is deployed selectively rather than broadly.”
Delivery
NeedyMantis is not an entry tool. Instead, operators drop it once they control a network. In one case, an operator used the Impacket toolkit to copy files from a network share and run them on a target machine.
The package always pairs a legitimate program with a malicious DLL. When the real program starts, Windows loads the fake DLL first. This is classic DLL sideloading. Microsoft saw the malware ride alongside Poedit, curl, Vim, and TightVNC. It also posed as Microsoft Office, Broadcom, Intel, and NVIDIA components.
Notably, Microsoft has not seen the NeedyMantis malware itself spread through a supply chain attack. Still, the company says such an attack “remains one possible means” of gaining the access needed to deploy it.
Infection Chain
First-Stage Loader
The sideloaded DLL has one job. It unpacks the next stage from a companion archive and hands off control. Along the way, it hides its strings and constant values from analysts. It also runs two checks to detect debuggers.
Encrypted Custom Archives
Each archive uses a custom format with XOR encoding and compression. The offsets and keys change from sample to sample. One archive held 11 files. Several were real 7-Zip and Sysinternals parts, which serve as camouflage. The rest carried the malware’s config, its network module, and a module loader. Each of those malicious files borrowed the name of a real Windows library.
Second Stage and Main Component
Next, a file with a PowerShell extension runs. In reality, it holds raw x64 shellcode. It unpacks the main component, which uses a stripped-down custom executable format. Therefore, standard tools cannot parse it without conversion. The main component then manages the server link and any extra modules.
Command-and-Control and Data Exfiltration
The first check-in looks like an ordinary HTTPS request. However, a cookie header smuggles out system data. That data includes the computer name, username, running processes, and installed programs.
After that, the connection switches to WebSockets. The two sides run a key exchange and then encrypt traffic with RC4. The main component supports a small set of commands. Operators can load or unload modules, pass data to them, and keep the session alive.
This design keeps the core small and flexible. Yet it also leaves a gap in what defenders know. Microsoft admits that “the capabilities of those modules remain unconfirmed.”

Attribution
Microsoft confirms that Storm-3069 used NeedyMantis. It assesses that this activity comes from China. However, it “has not attributed Storm-3069 to a Chinese nation-state actor.” Microsoft also found NeedyMantis activity beyond Storm-3069. So more than one group may share the tool, and that link remains suspected, not confirmed. Kaspersky, for its part, did not name an actor for the DAEMON Tools attack. It did note signs of a Chinese-speaking adversary.
Detection and Defense Guidance
Microsoft published indicators and Defender detections alongside its report. Beyond those, security teams can take these steps against the NeedyMantis malware:
- Hunt for trusted apps loading DLLs from odd folders, such as ProgramData subfolders named after vendors.
- Flag files whose extension does not match their content, like shellcode inside a .ps1 file.
- Watch for Impacket-style remote execution and file copies from network shares.
- Review outbound WebSockets traffic that starts with unusual cookie data.
- Update DAEMON Tools to a clean release and review any hosts that ran affected versions.
Ultimately, Microsoft calls NeedyMantis “a useful case study for understanding how threat actors establish and maintain long-term access within victim environments.” For defenders, the lesson is plain. The first breach is only the start, so hunt for what attackers leave behind.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!