Dual-RMM Phishing and PowerShell RAT Campaign Hits SLTTs
CIS CTI team published analysis of an active phishing campaign targeting U.S. state, local, tribal, and territorial (SLTT) organizations. The campaign leverages a custom PowerShell WebSocket RAT and dual RMM tools for credential theft and system compromise.
Who is affected
U.S. state, local, tribal, and territorial (SLTT) organizations
- Language
- EN