# NeedyMantis Malware Sustains Long-Term Network Breaches Across Multiple Sectors

*Published September 30, 2026*
*Source: [https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html](https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html)*

## Executive Summary

Microsoft has identified NeedyMantis malware as a tool used for long-term network breaches in sectors like telecommunications and government contracting. Originating as early as 2025, NeedyMantis operates through DLL sideloading and has been linked to potential Chinese interests.

## Article

Microsoft has identified a malware family known as NeedyMantis that is being used to maintain prolonged access in networks across various industries. This malware has been detected in telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its usage dates back to at least October 2025. The discovery was made during Microsoft's follow-up investigation on Kaspersky's report concerning a supply chain attack involving DAEMON Tools. This attack saw signed installers for the DAEMON Tools Lite program being compromised with malicious code between April and May 2026, which was later replaced by a clean version. The activity related to this attack is tracked by Microsoft as Storm-3069. Although NeedyMantis itself has not been seen spreading through supply chain attacks, it has been linked to this group. NeedyMantis typically arrives as a three-part bundle: a legitimate program, a malicious DLL, and an encrypted archive. Through DLL sideloading, the DLL is loaded when the program launches. The malware has been disguised as DLLs from widely-used applications like Microsoft Office and NVIDIA. In one notable case, the malware replaced WinSparkle.dll, which belongs to the Poedit translation tool. The main component of NeedyMantis, once activated, connects to a command-and-control server for further operations. Although Microsoft has not completely unraveled the functions of the additional modules it can load, it has identified a persistence module in older versions. The origin of Storm-3069's activity is believed to be China, but no direct link to a Chinese state actor has been confirmed. Google and Mandiant have also tracked related activity, identifying potential connections to Chinese interests. Microsoft has provided indicators of compromise and recommends specific configurations for Defender settings to detect and mitigate potential threats. Users of compromised DAEMON Tools installers are advised to uninstall the affected version and conduct a system scan.
