Microsoft Links NeedyMantis to Storm-3069 Campaign
Microsoft said NeedyMantis has been used to keep long-term access in a small number of targeted intrusions since at least October 2025, including telecoms, universities, medical nonprofits, intergovernmental organizations, and government contractors. It found the malware while following indicators from Kaspersky’s investigation into the DAEMON Tools Lite supply-chain attack and tied the activity to Storm-3069.
NeedyMantis rides in as a bundle: a legitimate program, a DLL with the same name as one the program expects, and an encrypted archive. When the program starts, it loads the fake DLL, which unpacks the next stage and opens an HTTPS connection that switches to WebSocket, letting operators load modules and move data after the first foothold.
If you trust signed installers or internal software shares, that trust path is part of the exposure now. Cleaning up the original installer may not remove the later-stage backdoor, so the durable problem is any machine where the malware already established post-compromise access.