
RADIO 007 · Wednesday · 4 min
NeedyMantis Malware: Microsoft Dissects the Daemon Tools Supply Chain Attack
0:00-4:42
transcript
show notes
www.osintinvestigate.com
Microsoft has analyzed NeedyMantis, a modular malware framework linked to targeted attacks following the May 2026 Daemon Tools supply chain compromise. In this episode, we examine how NeedyMantis works, its custom loaders and file formats, DLL sideloading, WebSockets-based command-and-control, and its role in maintaining long-term access to compromised environments. We also explore what Microsoft discovered about the threat actor tracked as Storm-3069 and why the attack highlights the risks of software supply-chain compromises.
Microsoft has analyzed NeedyMantis, a modular malware framework linked to targeted attacks following the May 2026 Daemon Tools supply chain compromise. In this episode, we examine how NeedyMantis works, its custom loaders and file formats, DLL sideloading, WebSockets-based command-and-control, and its role in maintaining long-term access to compromised environments. We also explore what Microsoft discovered about the threat actor tracked as Storm-3069 and why the attack highlights the risks of software supply-chain compromises.
links1


