Signed MSI delivers EndClient RAT while AutoIt loader runs in memory

EndClient RAT Targets NGOs via Signed MSI Installer

EndClient RAT arrives as a signed MSI named “StressClear.msi,” which abuses code-signing trust and SmartScreen gaps. The package decoys with a VeraPort component while an obfuscated AutoIt loader executes in memory, establishes the IoKlTr task, and opens a JSON-over-TCP C2. To reduce risk, restrict MSI installs, enforce SmartScreen blocking, instrument MSI→AutoIt lineage, and remove scheduled tasks used for persistence.

Read More

TikTok Algorithm Faces U.S. Control Data, Politics, and Security Concerns

TikTok’s future in the United States is undergoing a dramatic shift. Under a new deal, the app’s powerful recommendation algorithm will be retrained exclusively on U.S. user data, with a consortium of American investors taking control. While framed as a national security safeguard, experts warn the move could reshape TikTok’s content, amplify political influence, and…

Read More
Conference hall in Hanoi showing cybersecurity delegates at United Nations treaty signing

UN Cybercrime Pact to Sign in Hanoi: What Analysts Should Know

The UN is set to convene a landmark global cybercrime treaty signing in Hanoi, aiming to enhance cross-border cooperation and streamline investigations into ransomware, phishing and online trafficking. While supporters hail the pact as overdue, human-rights advocates and tech firms warn the broad language and choice of host country raise serious concerns about surveillance and enforcement.

Read More