NeedyMantis Malware Hid in Legitimate Apps to Maintain Access
Imazh i krijuar nga IA

NeedyMantis Malware Hid in Legitimate Apps to Maintain Access

Microsoft uncovered NeedyMantis, a malware using DLL sideloading in apps like Poedit, to maintain long-term access in breached networks, tracked as Storm-3069.

Microsoft has published a technical analysis of a malware family named NeedyMantis that attackers use to maintain long-term access inside networks they already breached. The malware has appeared in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental bodies, and government contractors, with activity going back to at least October 2025.

Microsoft discovered NeedyMantis while pursuing leads from Kaspersky's earlier investigation into a supply chain attack on DAEMON Tools. In that incident, official digitally signed installers for DAEMON Tools Lite carried malicious code between April 8 and May 5, 2026, when the developer replaced them with a clean version. Microsoft tracks the activity linked to that campaign as Storm-3069, a group that uses NeedyMantis, although the malware has not been observed spreading through a supply chain attack itself. The company notes that more than one group may be using the malware, and it has not yet determined whether all the activity comes from a single actor.

How NeedyMantis works is based on a technique called DLL sideloading. In the cases Microsoft examined, the malware arrived as a bundle of three items: a copy of a legitimate program, a malicious dynamic link library (DLL) file named after a file that program normally loads, and an encrypted archive with the same name as the DLL. When the user starts the legitimate program, it unknowingly loads the malicious DLL instead of the real one. Legitimate programs abused in this way include Poedit, a translation tool; curl, a data transfer utility; Vim, a text editor; and TightVNC, a remote access tool. The malicious DLLs have posed as files belonging to Microsoft Office, Broadcom, Intel, and NVIDIA software. In one detailed sample, the attackers replaced WinSparkle.dll, the update component used by Poedit.

After loading, the DLL unpacks the next stage from the encrypted archive and executes it, which then decodes the main malware component. That core connects to a command-and-control server over HTTPS and switches to a WebSocket for real-time communication. Through that channel, operators can load additional modules and send data to them, though Microsoft has not confirmed what those modules do. An older version from October 2025 installed a persistence module via Windows services, but the newer version's persistence method was not described. In one observed intrusion, an operator already inside the network used the Impacket toolkit to copy the bundle from a network share onto a target machine, indicating that the initial entry method may vary.

Storm-3069 is a temporary designation Microsoft assigns to emerging or uncharacterized groups. The company assesses that the activity appears to originate in China, citing targets that align with Chinese interests and the malware's use against only a few selected organizations, but it has not tied the group to a Chinese nation-state actor. Kaspersky earlier found Chinese-language text inside the DAEMON Tools malware but did not attribute it to any specific group. Google Threat Intelligence Group tracks the actor behind the DAEMON Tools campaign as UNC6863, and Mandiant described UNC6863 as a suspected China-nexus actor. It remains unclear whether UNC6863 and Storm-3069 are the same group.

Defenders can check for NeedyMantis using indicators Microsoft published, including SHA-256 hashes of the malicious DLL and encrypted archives, the command-and-control domain corp.tripswithengine[.]com, and the user agent firefox/21.0 hard-coded in the malware. Suspicious file paths include %ProgramFiles%\Poedit\WinSparkle.dll, %ProgramData%\USOShared\libcurl.dll, and several others under %ProgramData% pretending to be from Office, Broadcom, Intel, NVIDIA, and TightVNC. Microsoft Defender Antivirus detects the malware as TrojanDropper:Win64/NeedyMantis and Behavior:Win64/NeedyMantis. Hunting queries in Defender XDR and Microsoft Sentinel can look for these paths, the domain, and the user agent, but each query only searches the last seven days. Since the dated samples first appeared in October 2025 and May 2026, unchanged queries would miss older activity. A hit on the Poedit path alone is not proof of infection because WinSparkle.dll is a normal part of Poedit, so any file found there must be compared against the published hash.

Microsoft recommends enabling cloud-delivered protection, block at first sight, endpoint detection and response in block mode, network protection, automatic attack disruption, and two attack surface reduction rules. Checking outbound traffic for connections to the command-and-control domain is also advised, a step that does not require Defender. The company has not seen NeedyMantis delivered through the tampered DAEMON Tools installers, but anyone who downloaded the free DAEMON Tools Lite 12.5.1 during the affected period should uninstall it, run a full system scan, and install version 12.6 from the official website. For website owners and businesses, threats like NeedyMantis highlight the importance of hosting environments that monitor for unauthorized changes and provide intrusion detection, such as AEU Hosting's managed service, which includes proactive security monitoring for hosted sites.

Si të Mbroheni

  1. If you installed DAEMON Tools Lite between April 8 and May 5, 2026, uninstall it immediately, run a full antivirus scan, and download the latest version from the official website.
  2. Check your computer for any of the listed suspicious file paths, such as %ProgramFiles%\Poedit\WinSparkle.dll, and if found, compare its digital hash with the one Microsoft published.
  3. Keep your security software always turned on and updated, especially with cloud-based protection enabled.
  4. Monitor outbound network connections from your devices for any contact with the domain corp.tripswithengine[.]com.
  5. Be cautious of legitimate programs that suddenly ask for unusual permissions or show pop-ups from components you do not recognize.

Termat e Shpjeguar

  • DLL (Dynamic Link Library) A file that contains code and resources multiple programs can share, loaded when the program starts.
  • DLL sideloading A trick where an attacker places a fake file with the same name as a legitimate one a program expects, making the program load malware instead.
  • command-and-control (C2) server A computer controlled by hackers that sends instructions to compromised devices and receives stolen data.
  • WebSocket A technology that keeps a direct, ongoing connection open between a program and a server for real-time communication.
  • IOCs (Indicators of Compromise) Clues like file fingerprints or suspicious domain names that security tools use to detect a breach.
  • persistence mechanism A method malware uses to make sure it stays running on an infected machine even after a restart.

Shërbime AEU të lidhura

  • AEU-I Konsulencë IT dhe sigurie