Yaamlabs
Threat intel

NeedyMantis: hunting a backdoor that hides in trusted apps

Microsoft unpacked NeedyMantis, the modular backdoor used by the DAEMON Tools attackers. How it sideloads, how it talks to its server and how to hunt for it.

By Yaali. September 30, 2026, 6 min read, Threat intel, Windows.

Cover illustration of a circuit-line mantis hidden among software windows, with the Yaamlabs logo and the text: NeedyMantis hides a backdoor in trusted apps, since October 2025 in targeted intrusions

On September 28, Microsoft Threat Intelligence published an analysis of NeedyMantis, a modular backdoor used to keep long-term access to networks that attackers have already broken into. It has been in use since at least October 2025, against a small number of targets: telecommunications companies, universities, medical nonprofits, intergovernmental organizations and government contractors.

Microsoft found it while following indicators from the DAEMON Tools supply chain attack that Kaspersky disclosed in May. One operator is Storm-3069, Microsoft's name for the group behind that campaign. Microsoft assesses the activity comes from China but has not tied Storm-3069 to a Chinese state actor, and it has seen NeedyMantis outside that campaign too, so more than one operator may use it. If you work in one of those sectors, or installed DAEMON Tools Lite this spring, the hunting queries below are worth running this week.

How NeedyMantis runs: a legitimate program loads a planted DLL, which unpacks a shellcode stage from an encrypted archive, which starts the main backdoor that connects over HTTPS and upgrades to a WebSocket

How it works

NeedyMantis arrives as three files dropped side by side: a genuine copy of a signed program, a malicious DLL named after a library that program loads, and an encrypted archive with the same name as the DLL, minus the extension. Windows looks in the program's own folder first when it resolves a DLL, so starting the program loads the attacker's library. This is DLL sideloading.

The host programs Microsoft saw are Poedit (a translation editor), curl, Vim and TightVNC. The DLL names copy each program's real dependency, such as WinSparkle.dll, Poedit's updater library, or they pose as Microsoft Office, Broadcom, Intel and NVIDIA components (dbghelp.dll, jli.dll, nvml.dll). The folders are chosen to look ordinary: %ProgramData%\USOShared is a real folder used by the Windows Update Session Orchestrator.

The first-stage DLL reads the archive, which is XOR encoded and compressed with the Windows RtlDecompressBuffer routine. The XOR keys and offsets change from sample to sample, so a static signature for one archive does not catch the next. Inside the Poedit package, a file called encryptbase64.ps1 was not PowerShell at all but x64 shellcode: the second-stage loader. That stage unpacks the main component, which ships in a stripped-down custom executable format that the loader converts back into a standard Windows PE (Portable Executable) file before it runs, so the archive on disk holds no ordinary executable for a scanner to parse.

The main component's supporting modules take the names of Windows system libraries: dnsapi.dll holds the configuration, ws2_32.dll handles WebSocket traffic and msvcrt140.dll carries shellcode for loading modules. Those names only make sense in System32, so finding them next to a copy of Poedit or curl is a strong signal.

Command and control

The backdoor opens with an HTTPS GET to its server, corp.tripswithengine[.]com on port 443 at the path /library/zip/, with a hard-coded user agent string of Firefox/21.0. System details ride in a Set-Cookie header as compressed, Base64-encoded JSON: computer name, user name, the process and parent process names, a process list and a listing of installed program folders.

The connection then upgrades to a WebSocket and switches to a binary protocol. After an RC4 key exchange, each message carries a 44-byte header XOR encoded with a fresh 16-byte key, and a compressed, optionally RC4 encrypted payload. The server can load a module (command 1020), unload one (1030) or pass data to it (1050). In the sample Microsoft analysed, the beacon slept 300 seconds between contacts. Microsoft could not confirm what every module does, but an older variant carried a module named is that installed a Windows service for persistence.

What attackers are doing

NeedyMantis is not an initial access tool. In one incident Microsoft describes, the operator already had access and used the Impacket toolkit, a set of Python tools for remote Windows administration that attackers use for lateral movement, to copy the program, DLL and archive from a network share and start them on the target. Microsoft reads the narrow victim list, which fits Chinese interests, as deliberate target selection.

The DAEMON Tools campaign followed the same selective pattern. Kaspersky found that installers on the official DAEMON Tools site were trojanized from April 8, 2026, in builds 12.5.0.2421 through 12.5.0.2434, and signed with the developer's valid certificates. Three files were altered: DTHelper.exe, DiscSoftBusServiceLite.exe and DTShellHlp.exe. Thousands of machines were infected, but the second stage went to only a small subset of them. The vendor released a clean build, 12.6.0.2445, on May 6.

The earliest NeedyMantis archive in Microsoft's indicators, for the curl variant, was first seen on October 3, 2025, six months before the DAEMON Tools installers were poisoned. The Poedit samples were first seen on May 21 and 23, 2026, soon after that campaign was exposed.

What to do

There is no patch for this; the job is to find it and to make sideloading harder.

Four hunting and hardening steps: check DAEMON Tools, hunt for planted DLLs, search network logs for the C2 domain and user agent, then turn on the Defender settings Microsoft recommends

  1. Check for DAEMON Tools Lite. Any machine that installed or updated it between April 8 and May 5, 2026 ran a trojanized build. Upgrade to 12.6.0.2445 or later, then run the checks below: an upgrade replaces the program files but does not undo what the tampered build already installed.
  2. Hunt for the planted DLLs. In Microsoft Defender XDR advanced hunting, query DeviceFileEvents for these names in these folders: WinSparkle.dll under Program Files\Poedit or Program Files (x86)\Poedit; libcurl.dll under ProgramData\USOShared; vim64.dll under ProgramData\VIM or ProgramData\TightVNC\VIM; dbghelp.dll under ProgramData\office or ProgramData\broadcom; jli.dll under ProgramData\Intel; nvml.dll under Program Files\modifiable or ProgramData\ics. Microsoft's post has the full query; other EDR tools can run the same file search.
  3. Search network logs. Look in DNS, proxy and firewall logs for corp.tripswithengine[.]com and for any request with a Firefox/21.0 user agent. Firefox 21 shipped in 2013, so any hit today needs explaining. In Microsoft Sentinel, check CommonSecurityLog for RequestClientApplication contains "Firefox/21.0".
  4. Check the hashes. Search for these SHA-256 values: e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e (first-stage WinSparkle.dll), 9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef (WinSparkle archive) and c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77 (libcurl archive).
  5. Look for Impacket. Defender alerts named "Ongoing hands-on-keyboard attack via Impacket toolkit" or the HackTool:Win32/Impacket detection on a host with any of the files above mean someone was working hands-on inside your network: treat it as an active intrusion.

Microsoft Defender Antivirus detects the malware as TrojanDropper:Win64/NeedyMantis and Behavior:Win64/NeedyMantis. Microsoft also recommends turning on cloud-delivered protection with block at first sight, running EDR in block mode, enabling network protection in Defender for Endpoint, and configuring automatic attack disruption in Defender XDR. Two attack surface reduction rules are relevant: "Block executable files from running unless they meet a prevalence, age, or trusted list criterion" and "Block execution of potentially obfuscated scripts". Run them in audit mode first, since the prevalence rule also flags rare in-house tools.

If you find a hit, isolate the host rather than deleting files, since the backdoor loads modules on demand and you need to know which ones it received. Then find how the files arrived: the Impacket session implies a compromised account with admin rights on that host. Reset that account and any service accounts it could reach, and review the network shares used for staging.

Why the file path matters more than the file

The program is genuine and signed, the DLL names are real and the archive changes per sample, so hashes and signatures miss it. The location does not fit: curl's library in a Windows Update folder, ws2_32.dll outside System32. A rule that alerts when a system DLL name loads from anywhere but its normal path, or when a signed program runs from ProgramData, catches this family and other sideloading tools built the same way.

We write and tune that kind of detection in security operations, and we check whether a planted DLL would get this far in safeguarding and hardening reviews. To have these hunts run on your estate, open the chat: Yaali, our AI agent, will pass your question to an engineer.


Sources: Microsoft Security Blog, SecurityWeek, Dark Reading, Cybersecurity News, Kaspersky, Help Net Security.

Read next

Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.