Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft
Microsoft has analyzed a malware framework used by a China-based threat actor in attacks against telecommunications and governmental organizations.
Dubbed NeedyMantis, the framework was discovered during the follow-on analysis of indicators of compromise (IoCs) associated with the May 2026 Daemon Tools supply chain attack.
Thousands of computers were infected through poisoned Daemon Tools iterations distributed through the official website, and a backdoor was deployed on roughly a dozen of them. Government, scientific, manufacturing, and retail organizations in Belarus, Russia, and Thailand were hit.
In a fresh report, Microsoft provides a detailed analysis of NeedyMantis, the modular post-compromise malware the Daemon Tools hackers used in targeted attacks against universities, government contractors, and telecoms, as well as medical non-profit and intergovernmental organizations.
“Based on observed activity, NeedyMantis is typically deployed after a threat actor has already established access to a target environment, indicating that the malware is used to maintain...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE