Follow the latest coverage, related explainers and connected technology stories.
Microsoft Threat Intelligence has revealed NeedyMantis, a modular malicious software framework used after compromising the target environment to maintain access and conduct subsequent operations. Microsoft observed its use in limited operations targeting telecommunications entities, universities, and medical and government organizations, with indicators linking the activity to China-based entities without attributing it to a specific government entity.
Kaspersky detected a campaign that began in mid-August 2026 and exploits movie torrent files, including The Odyssey, to spread malware capable of stealth, persistence, and bypassing UAC, while using the Solana blockchain to discover command-and-control servers.
Microsoft Defender Experts found that the MacSync Stealer malware rapidly changes the domains of its infrastructure, but its execution, communication, and data-collection patterns remained consistent enough to link more than 30 domains. The investigation focuses on behavioral indicators that defenders can use to detect attacks even after server addresses change.