A China-Linked Group Has Been Living Inside Networks for a Year Using Tools You Trust
Cybersecurity

A China-Linked Group Has Been Living Inside Networks for a Year Using Tools You Trust

Microsoft tied a malware family called NeedyMantis, deployed by a China-nexus group hiding inside sideloaded DLLs for tools like Poedit and curl, to a persistence campaign against telecoms, universities, and government contractors dating back to October 2025.

PublishedSeptember 29, 2026
Read time5 min read
Share

Discovered by accident, while investigating something else

NeedyMantis did not surface because someone went looking for it directly. Microsoft found it while investigating the DAEMON Tools supply chain compromise, a separate incident in which signed installers for the popular disc-imaging utility carried malicious code between April and May 2026. That investigative thread led researchers to a distinct malware family, deployed by a group Microsoft tracks under the temporary designation Storm-3069, designed for one specific job: keeping access to networks that were already breached, long after the original intrusion.

Microsoft assesses the activity likely originates in China, though the company stopped short of formally attributing it to a specific nation-state actor or known APT group. Separately, Google tracks the operator behind the DAEMON Tools compromise as UNC6863, describing it as a suspected China-nexus actor. Whether UNC6863 and Storm-3069 are the same group, affiliated groups, or simply two Chinese operations that happened to surface from the same investigation remains unconfirmed, but the overlap in timing and tradecraft is close enough that defenders should treat the two campaigns as related until proven otherwise.

The trick is hiding inside software you already trust

NeedyMantis works through DLL sideloading, a technique where a malicious DLL file is placed alongside a legitimate, signed executable in a way that tricks the operating system into loading the attacker's code instead of, or alongside, the real library. Microsoft identified the technique being used against Poedit, a widely used open source translation editing tool, by replacing its legitimate WinSparkle.dll update library with a malicious version. Other legitimate tools implicated in the campaign include curl, the Vim text editor, and TightVNC remote access software, all common, unremarkable utilities that a security team would rarely think to flag as suspicious on their own.

That choice of cover is deliberate and effective. Endpoint detection tools are tuned to flag unusual or unsigned executables, not to interrogate why a well-known, digitally signed tool like curl or Vim is present on a system, because those tools are legitimately everywhere in developer and IT environments. The malware bundle itself ships in three parts, the legitimate software, the malicious DLL, and an encrypted archive, and establishes command-and-control over HTTPS before transitioning to WebSocket connections, a combination chosen specifically to blend into ordinary web traffic rather than stand out against it.

The target list reads like a soft-target playbook

The organizations NeedyMantis has targeted, telecommunications companies, universities, medical nonprofits, intergovernmental organizations, and government contractors, share a common profile: institutions that hold valuable strategic or research data but that historically invest less in security operations maturity than a comparably sized financial services or technology company. Telecoms sit at the center of communications infrastructure and are a perennial espionage target. Universities and medical nonprofits often run distributed, loosely governed IT environments where a stray sideloaded DLL on a research lab machine can go unnoticed for a very long time.

That mismatch between target value and security maturity is precisely what makes a persistence-focused campaign like this one viable for close to a year without detection. Storm-3069 is not trying to smash and grab. The entire design of NeedyMantis, quiet C2 channels, legitimate-tool camouflage, minimal footprint, is built for an operator who values staying inside a network over any single, immediate payoff, which is the operational signature of espionage-oriented activity rather than financially motivated crime.

Why patching the original hole is not enough

The most important detail in this disclosure is what it implies about incident response completeness. NeedyMantis was found downstream of the DAEMON Tools supply chain compromise, meaning organizations that were hit by that initial incident, patched the affected DAEMON Tools installer, and considered the matter closed may still have had a persistence mechanism like NeedyMantis quietly running in the background the entire time. Patching the entry point closes the door the attacker originally used. It does nothing about whatever they left behind once they were already inside.

That gap between remediating an entry vector and confirming an environment is actually clean is one of the most common and most expensive mistakes in incident response, and it is exactly the gap a sophisticated, persistence-focused actor is counting on. A team that treats a supply chain compromise as resolved once the vulnerable software is updated, without a dedicated post-compromise hunt for exactly this kind of sideloaded persistence tooling, is leaving the most patient category of attacker with everything it needs to stay put.

What to hunt for now

If your organization used DAEMON Tools between April and May 2026, or runs Poedit, curl, Vim, or TightVNC anywhere in your environment, this is worth a dedicated hunt rather than a routine scan. Check for unexpected DLL files sitting alongside these legitimate executables, particularly any WinSparkle.dll instances tied to Poedit installations that do not match expected file hashes, and review outbound HTTPS and WebSocket connections for anomalous, low-and-slow traffic patterns rather than the high-volume exfiltration signatures most detection rules are tuned to catch.

More broadly, this incident is a good prompt to formalize a standing practice: any confirmed supply chain compromise in your environment should trigger an automatic, time-boxed post-compromise hunt for persistence mechanisms, not just a patch-and-close workflow. The organizations most exposed to NeedyMantis right now are not the ones who missed the original DAEMON Tools warning. They are the ones who responded correctly to that warning and assumed correct response meant the incident was over.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#needymantis#storm-3069#china#dll-sideloading#espionage