NeedyMantis Malware Framework Used in Targeted Attacks Against Various Organizations
The NeedyMantis malware framework was used in targeted attacks against various organizations by a China-based threat actor, according to Microsoft's analysis. The framework was discovered during an investigation into the Daemon Tools supply chain attack in May 2026, which infected thousands of computers through poisoned software iterations distributed on the official website.
The malware was used to maintain long-term access and support follow-on operations, and has been used since at least October 2025. NeedyMantis is a modular post-compromise malware with a custom architecture, consisting of multiple loaders, encrypted file archives, and executable file formats designed to evade detection.
The infection chain starts with a first-stage loader and a file archive packaged alongside legitimate software, which abuses DLL sideloading to execute the loader. The second-stage loader extracts embedded data, decodes and decompresses it, and loads a minimized version of a PE file in the form of a DLL.
The main component of NeedyMantis orchestrates command-and-control communication through WebSockets and can load or unload modules, dispatch data to modules, and turn off flags. The capabilities of additional modules remain unconfirmed.