A framework whose modules unload themselves, and a year inside telecommunications networks
Microsoft documented NeedyMantis on 28 September: a modular post-compromise framework found while following indicators from the DAEMON Tools supply chain compromise. Its design choice - load a capability, use it, unload it - is what makes the scope of any intrusion it supported hard to establish after the fact.

Microsoft Threat Intelligence published an analysis of a malware framework called NeedyMantis on 28 September 2026 [1]. The framework is not how intruders get in. Microsoft describes it as typically deployed after a threat actor has already established access to a target environment, combining custom loaders, encrypted archives and extensible components to maintain long-term access and support follow-on operations [1]. Observed activity dates back to at least October 2025 [1].
The detail that matters for incident response is architectural. Operators can load modules, dispatch data and unload modules without replacing the core implant, and Microsoft records the capabilities of those modules as unconfirmed [1]. A responder who recovers the implant recovers the delivery mechanism, not the list of what was run through it.
How it was found
Microsoft identified NeedyMantis while analysing indicators from the DAEMON Tools supply chain compromise that Kaspersky had reported earlier in the year [1]. That compromise is worth restating because it is the entry point in at least one cluster. From 8 April 2026, the official distribution channel for DAEMON Tools served trojanised Windows installers – versions 12.5.0.2421 through 12.5.0.2434 – with three tampered binaries digitally signed by the developer, AVB Disc Soft [2][4].
Kaspersky’s researchers Igor Kuznetsov, Georgy Kucherin, Leonid Bezvershenko and Anton Kargin described a staged operation: a broad information collector gathering MAC address, hostname, DNS domain, running processes, installed software and system locale; then, for selected victims, a minimalistic backdoor able to download files, run shell commands and execute shellcode in memory; and in one case a more capable implant supporting HTTP, UDP, TCP, WSS, QUIC, DNS and HTTP/3 [2]. Distribution reached more than 100 countries, concentrated in Russia, Brazil, Turkey, Spain, Germany, France, Italy and China, while the advanced payloads went to roughly a dozen machines in government, scientific, manufacturing and retail organisations in Russia, Belarus and Thailand [2][5].
The shape of that operation – mass collection, then selection, then a small number of deep implants – is the part worth noting. Approximately one in ten affected systems belonged to an organisation rather than an individual [5]. The breadth was a filter, not the objective.
On attribution Kaspersky was careful: artefacts suggesting that the threat actor behind this attack is Chinese-speaking were identified, and the campaign was not attributed to any known actor [2][3]. Microsoft is similarly bounded. It designates one observed operator Storm-3069, associated with the DAEMON Tools campaign, assesses the activity originates from China, and states it has not attributed Storm-3069 to a Chinese nation-state actor, adding that the malware might be used by more than one operator [1][10]. R3KONX reports those assessments as the vendors’ own and asserts nothing beyond them.
What the framework does
The delivery technique is DLL sideloading against legitimate applications – Poedit, curl, Vim and TightVNC are named – with malicious libraries masquerading as components from Microsoft, Broadcom, Intel or NVIDIA [6][8]. In observed cases the operators used the Impacket toolkit to copy the legitimate software, the malicious library and the encrypted archives from network shares [1]. From there a first-stage loader unpacks a custom encrypted archive, a second-stage loader decodes the core, and the main component takes over command and control [1][9].
The command channel is designed to look ordinary and then stop looking like HTTP at all. The initial beacon is an HTTPS request carrying compressed, encoded system details inside a Set-Cookie header; the session then upgrades to WebSockets running a custom binary protocol with XOR encoding, compression and optional RC4 encryption [1][6]. Microsoft published the observed command server, corp.tripswithengine[.]com, and notes an outdated firefox/21.0 user agent in network logs [1][8].
None of this is novel individually. Sideloading, encrypted archives and WebSocket command channels are all established. What is operationally significant is the combination of commodity technique with modular capability and a long residence: the tooling is cheap to build, hard to attribute, and designed so that the evidence of what it did does not persist alongside the evidence that it was there.
The scope problem
One publisher calculates the residence inside telecommunications networks at close to a year, reasoning from Microsoft’s earliest observed activity in October 2025 to the September 2026 disclosure, and argues that the full scope of what was accessed or exfiltrated before detection should be treated as unknown until proven otherwise [7]. That figure is a publisher’s arithmetic rather than a Microsoft statement, and it is reported here as such. The reasoning behind it is sound, and it is the right default for a framework built to unload its own capabilities.
No source read for this article gives a victim count, and none is asserted. The sectors Microsoft names – telecommunications providers, universities, medical nonprofits, intergovernmental organisations and government contractors – describe a collection posture rather than a market [1][6]. Telecommunications and intergovernmental bodies are transit points: an intruder who holds them reaches third parties who were never themselves compromised.
What to do
- Hunt the sideloading, not the file name. Look for unexpected or newly appearing DLLs beside legitimate binaries, particularly where a library claims a vendor identity inconsistent with its directory [8][9].
- Block and alert on the published command infrastructure at the network boundary, and search network logs for the outdated firefox/21.0 user agent string Microsoft records [1][8].
- Inspect the WebSocket upgrade, not only the first request. A session that begins as HTTPS and converts to a binary WebSocket protocol will pass most egress rules written around HTTP methods and content types [1][6].
- Treat a recovered implant as the floor of an investigation, not the ceiling. Because modules load and unload without replacing the core, absence of a capability on disk is not evidence it was never used [1][7].
- Review third-party software installed from vendor sites during April and early May 2026 against the affected DAEMON Tools build range, including on machines that are no longer in service [2][5].
- Signed does not mean trustworthy. The installers carried a valid developer certificate, so code-signing policy alone would not have stopped this; pair it with reputation and behavioural controls [2][4].
The R3KONX view
The interesting claim in Microsoft’s write-up is not the malware but what it implies about the detection problem. Post-compromise frameworks are the part of an intrusion defenders see last and reconstruct worst, because by the time one is found the useful evidence of what it carried has been unloaded. An adversary that invests in modularity is making an explicit bet against forensic reconstruction, and on current evidence it is a good bet.
For this region the relevant detail is that a supply chain compromise seeded from a consumer utility reached targeted organisations in Thailand, alongside Russia and Belarus [2][5]. That is the mechanism to plan around rather than the geography: widely installed third-party software on engineering and administrative workstations, signed, trusted, and rarely inventoried. Malaysian and ASEAN organisations with university, telecommunications or government-contractor profiles sit in exactly the sector set Microsoft names. The question for a security team this week is not whether NeedyMantis is in the estate. It is whether an investigation could show it had not been.
Sources
Every R3KONX article cites its primary material. 10 sources, in order of first citation. Links open the original publication.
- NeedyMantis: Unpacking a post-compromise malware family used in targeted operations Microsoft Threat Intelligence · 2026-09-28
- Popular DAEMON Tools software compromised Securelist, Kaspersky (Kuznetsov, Kucherin, Bezvershenko, Kargin) · 2026-05
- Kaspersky identifies ongoing supply chain attack on official DAEMON Tools website distributing backdoor malware Kaspersky (press release) · 2026-05-05
- Attackers compromised Daemon Tools software to deliver backdoors Help Net Security · 2026-05-06
- Kaspersky uncovers targeted DAEMON Tools supply chain attack affecting manufacturing, government sectors Industrial Cyber · 2026-05
- Microsoft Finds New Malware Used by Hackers to Maintain Secret Access Inside Target Networks Cybersecurity News · 2026-09-28
- Microsoft Exposes China NeedyMantis Spy Tool: Year Inside Telecoms Left Theft Scope Unknown Tech Times · 2026-09-29
- Microsoft Details NeedyMantis Windows Backdoor: DLL Sideloading Detection and Hunting WindowsForum · 2026-09-28
- Threat Advisory: NeedyMantis Malware UV Cyber · 2026-09-30
- Microsoft Details NeedyMantis Post-Compromise Malware Cyber Kendra · 2026-09-28
This article was researched and written by the R3KONX analysis desk from the cited primary material. Methodological caveats: Microsoft states it has not attributed the activity to a nation-state actor and that more than one operator may use the malware, and that framing is preserved here; the capabilities of the framework's loadable modules are recorded by Microsoft as unconfirmed; no victim count has been published by any source read; and the dwell-time figure is a publisher's calculation from Microsoft's earliest observed activity, not a Microsoft statement. Corrections: event@r3konx.asia
