Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-29 · updated: 2026-09-29 · tags: [incident, defence, supply-chain] · confidence: high · severity: high · affected_sectors: [defence] · au_impact: true

Microsoft Threat Intelligence disclosed NeedyMantis, a modular post-compromise malware family observed in a limited number of targeted intrusions affecting telecommunications organisations, universities, medical nonprofits, intergovernmental organisations and government contractors. It was found while pivoting from indicators in Kaspersky's DAEMON Tools supply-chain investigation, whose official signed installers carried malicious code from 8 April 2026 until the developer replaced them on 5 May; Microsoft tracks that activity as Storm-3069, assesses it originates from China without attributing it to a Chinese nation-state actor, and says NeedyMantis may be used by more than one operator. The framework combines several loaders written in C++ and x64 shellcode, a custom encrypted archive format, a custom executable file format and modular components, and has been seen masquerading as Microsoft Office, Broadcom, Intel and NVIDIA DLL components. Microsoft stresses the link to DAEMON Tools is narrower than it first appears: it has not observed NeedyMantis itself delivered through a supply chain, only that supply-chain access is one route to the point where the malware is installed. The victimology and limited deployment indicate selective rather than broad use. Users of the affected installers should move to DAEMON Tools 12.6.0.2445 or later.

Attribute Detail
Sector Defence
Date 2026-09-29
Source Microsoft Threat Intelligence
Reliability Tier 1