I read The Hacker News on September 29, 2026. Microsoft is the lab they cite.

The malware name is NeedyMantis. Microsoft says it is used to keep a foothold after a network is already open. They describe a small set of victims: phone carriers, campuses, medical charities, groups that sit between governments, and firms that contract for governments.

The feed stops at the words at least, so I am not dating the first time they saw it. I am also not describing how the program hides. That stays in Microsoft's paper.

Source I used: The Hacker News. The link is under this column.