```html ```
top of page

Microsoft Just Named NeedyMantis. It Rode In Through a Translation App's Updater, Hit Telecoms, Universities and Medical Nonprofits, and We Missed the May Supply-Chain Attack That Started It.

Writer: Patrick Duggan
Patrick Duggan
1 hour ago
5 min read

On September 28, Microsoft Threat Intelligence published a teardown of a malware family it calls NeedyMantis. It is a modular backdoor for keeping long-term access to a network after someone has already broken in, and Microsoft has seen it used against telecommunications companies, universities, medical nonprofits, intergovernmental organizations and government contractors.


The actor Microsoft tracks is Storm-3069. Microsoft assesses the activity comes from China. It has not tied Storm-3069 to a specific Chinese state group, and it says the malware may be in the hands of more than one operator. We are not going to go further than Microsoft did on attribution.


We were not early on this. We were one day late on NeedyMantis and five months late on the supply-chain attack that led to it. Both of those are in this post, after the part you can use.



What happened


Microsoft found NeedyMantis while following up on indicators from the DAEMON Tools supply-chain compromise. Kaspersky disclosed that one in early May: from April 8, the official DAEMON Tools site served signed, trojanized Windows installers for about a month. Those installers pulled down an information collector that ran on a large number of consumer and business machines around the world.


NeedyMantis is what comes after the collector, on the machines somebody decided were worth keeping. Microsoft dates related activity back to at least October 2025.


The loader Microsoft took apart is a rogue WinSparkle.dll. WinSparkle is a small, legitimate open-source library that Windows apps use to check for their own updates. In Microsoft's sample it replaced the updater component of Poedit, a translation editor. The app starts, loads what it thinks is its updater, and the updater is the backdoor. Microsoft also lists libcurl.dll, vim64.dll, dbghelp.dll, jli.dll and nvml.dll as file names the loaders have used. Every one of them is a name you would expect to find sitting next to a real program.


The loader hides its strings, resolves Windows functions at runtime, and checks whether a debugger is attached. It unpacks custom encrypted archives and a custom executable format, then pulls in modules on command. The backdoor checks in over HTTPS, then switches to a WebSocket channel encrypted with XOR and RC4. The sample Microsoft analyzed talked to corp.tripswithengine[.]com on port 443 at the path /library/zip/, with a hard-coded user agent claiming to be Firefox 21. Firefox 21 shipped in 2013. Hands-on-keyboard activity in the same intrusions included Impacket.



The opinion: the updater is the soft surface


Kaspersky counts four supply-chain compromises it has investigated in 2026: eScan, Notepad++, CPUID and DAEMON Tools. We wrote up Notepad++ in February. Every one of them came in through trusted software being installed or updated. NeedyMantis is the same move one level down: not a poisoned download site, but a poisoned updater library inside an app that was installed on purpose.


The hard perimeter did its job in every one of these. The signed installer was really signed. The app really was Poedit. The DLL really had the name the app expected. What failed is the part nobody owns: the small helper that runs with the app's trust and that nobody inventories. We keep calling that the soft surface, and it keeps being where the damage comes from.


The victim list matters here too. Telecoms, universities, medical nonprofits. Two of those three do not have a detection-engineering team and will not be buying Defender XDR's top tier this quarter. Microsoft's post is good and it is written for Microsoft customers. The indicators are the part that travels to everyone else, and that is what our feed is for.



What a cash-poor defender does about it




Block and hunt the four indicators. The C2 host corp.tripswithengine[.]com and three SHA-256 hashes: the WinSparkle.dll loader e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e, and two encrypted archives, 9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef and c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77. All four are in our free domains.csv and hashes.csv right now at confidence 80 to 85, which clears the default floor of 30. We checked the downloaded files, not just the database.


Hunt for the Firefox 21 user agent in proxy logs. Almost nothing legitimate still sends it. A hit is worth a look even if the destination is not on any list.


Inventory updater DLLs, not just apps. Look for WinSparkle.dll, libcurl.dll, dbghelp.dll, jli.dll and nvml.dll in places where the parent application does not ship them, or with hashes that do not match the vendor's. dbghelp.dll outside System32 and outside a debugger install is a classic side-load tell.


If DAEMON Tools 12.5.0.2421 through 12.5.0.2434 ever ran on a machine, treat that machine as a lead, not a closed ticket. The first-stage collector decided who got the second stage. NeedyMantis is the second stage.





What we had, and when


Our vendor-blog harvester read Microsoft's post and wrote all four indicators into our index at 18:47 UTC on September 29, about a day after Microsoft published. It put the name NeedyMantis in a free-text description, but left the malware family and actor fields empty. The indicators were in the feed. Anyone searching our index by family or actor would not have found them. We then wrote an attributed batch with the family, the actor and the source, and confirmed it reads back.


That is ingest, not detection. Microsoft saw this first, from inside the victims. Our timestamp is when we read their post.


The part we are less happy about: we never covered the DAEMON Tools compromise in May. We searched our own archive three different ways to be sure. It is not there. A signed installer from an official site pushing a collector onto machines worldwide is exactly the story we exist to tell, and we did not tell it. The indicators from that campaign are the ones that would have put a defender five months ahead of today's post, and they were never in our feed under a name you could find.


Also found while putting this together: the same harvester lane was writing some things that are not domains, such as executable file names, into the domain list. That is being fixed separately, and we will say what shipped.


Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.




Every indicator in this post is in the feed. Free.

1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.



Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=microsoft-just-named-needymantis-it-rode-in-through-a-translation-app-s-updater-hit-telecoms-univ



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page