Microsoft details NeedyMantis malware linked to 2026 Daemon Tools supply-chain attack
Microsoft has published a closer look at NeedyMantis, a modular malware framework tied to the May 2026 Daemon Tools supply-chain attack that reportedly infected thousands of computers and enabled targeted follow-on intrusions.
TLDR
Microsoft has published a technical analysis of NeedyMantis, a modular malware framework linked to the May 2026 Daemon Tools supply-chain attack. SecurityWeek reports the poisoned software distributed through the official Daemon Tools website infected thousands of computers, while a backdoor was deployed on roughly a dozen of them. Microsoft says NeedyMantis is typically used after attackers already have access, helping them keep long-term footholds and support later operations. The framework uses multiple loaders, encrypted archives, custom executable formats, and modular C++ and x64 shellcode. Microsoft says its chain starts alongside legitimate software, uses DLL sideloading, and ends with a main component that communicates over WebSockets and can manage additional modules. Microsoft says NeedyMantis has been seen since at least October 2025.
Combined views
604
1 Source, first seen 2h ago