
The Center for Internet Security® (CIS®) Cyber Threat Intelligence (CTI) team identified an active phishing campaign that is opportunistically targeting multiple U.S. State, Local, Tribal, and Territorial (SLTT) government networks by delivering a custom PowerShell WebSocket remote access trojan (RAT) followed by dual remote monitoring and management (RMM) tools for persistent access.
The CIS CTI team assesses this campaign is almost certainly a variant wave of the financially motivated cargo theft and freight fraud operation previously documented by Proofpoint Threat Research based on an exact SHA256 hash match between the Pulseway installer and multiple overlapping delivery, command and control (C2), and dual-RMM tradecraft. Across four delivery variants observed, the cyber threat actors (CTAs) continue to upgrade their malware and delivery tradecraft, including by shifting to encrypted C2, User Account Control (UAC) bypass, and per-build payload randomization. These updates indicate an operation in active development.
The campaign also abuses legitimate Google Drive share notifications to bypass email authentication, hosts lure pages and payloads on Google Cloud Storage (GCS), and uses the WebSocket RAT to enable real-time hands-on-keyboard operator interaction prior to RMM installation.
Having confirmed these campaign elements along with C2 beaconing observed across multiple U.S. SLTT networks, the CIS CTI team assesses the CTAs will likely continue to opportunistically target U.S. SLTT organizations.
Overview of the Campaign
The CIS CTI team first identified this activity after a member of the Multi-State Information Sharing and Analysis Center® (MS-ISAC®) shared two phishing emails their organization received. The member also shared the VBS dropper, two PowerShell WebSocket RATs and associated logs, and the Pulseway and ScreenConnect RMMs the CTAs installed after the member detonated the phishing emails in a controlled sandbox. Extensive infrastructure pivoting from these initial samples identified additional delivery variants sharing a common WebSocket RAT codebase and back-end infrastructure. Subsequently, the same member later submitted a fourth, more advanced variant, indicating this is an active and continuously updated campaign.
CIS CTI assesses it is almost certainly the same campaign Proofpoint Threat Research documented targeting the transportation and logistics sector in February and March 2026. Once initial access and persistence were established through redundant RMM installation, Proofpoint observed the CTAs identifying and exploiting user access to financial systems, such as banking portals, payment platforms, and accounting software.
The two phishing emails CIS CTI received were addressed to an employee at a U.S. SLTT organization, with a large CC list spanning multiple sectors, indicating broad, indiscriminate distribution rather than deliberate targeting of that organization. Subsequent analysis of Albert Network Monitoring and Management sensor data and Malicious Domain Blocking and Reporting (MDBR) data identified C2 beaconing to confirmed campaign infrastructure from multiple additional U.S. SLTT member networks, indicating the campaign’s impact likely extends beyond the initial U.S. SLTT organization.
Given this observed multi-member impact and the expanded phishing email recipient list spanning multiple non-transportation sectors, the CIS CTI team assesses CTAs are likely broadening their targeting beyond the transportation and logistics sector to include U.S. SLTT organizations.
Inside the Four PowerShell RAT Variants
Variant 1 appeared in both the original MS-ISAC member submission and across the majority of samples identified through the CIS CTI team’s investigation. In this variant, the operator uses a two-stage VBS dropper with an embedded Base64 PowerShell RAT and scheduled task persistence. Once the CTA establishes persistence, they transition to hands-on-keyboard activity, issuing commands via the PowerShell RAT to install ScreenConnect and Pulseway RMMs for sustained access.
Variant 2 takes a different approach in packaging the PowerShell RAT as a compiled executable inside an MSI installer, which runs the RAT in memory with no on-disk staging or persistence mechanism. This PowerShell RAT presents the victim with a decoy Docusign “Generate Signing Key” Windows Forms graphical user interface (GUI) to disguise its C2 activity while the RAT beacons in the background.
Variant 3 uses a different, stealthier VBS technique. Rather than Base64 encoding the PowerShell RAT payload, the dropper uses Scripting.FileSystemObject to write the PowerShell RAT line by line to %TEMP%\agent.ps1. This PowerShell RAT variant is self-elevating and self-hiding, handling UAC elevation and Windows console suppression entirely by itself rather than relying on the VBS wrapper.
Variant 4, the most recently identified after the member reported an additional phishing email, introduces the most significant capability escalation in the campaign. Where the earlier variants embed the PowerShell RAT directly in their droppers, Variant 4 uses a multi-stage fetch-and-stage delivery chain and adds three new capabilities: encrypted command-and-control, a genuine UAC bypass, and per-build payload randomization.
The chain begins when an obfuscated VBS dropper retrieves a loader from a GCS staging bucket, and the XOR and Base64-encoded loader deobfuscates the RAT to a randomly named file in %TEMP% before runing it hidden. The resulting RAT connects over encrypted WebSocket to wss://360securityaccess[.]com, a shift from the unencrypted ws:// on a bare IP used by earlier variants, and on the operator’s elevate command compiles inline C# to perform a COM elevation-moniker UAC bypass, relaunching with administrative privileges and no UAC prompt. Each build uses a freshly randomized XOR key and variable set, producing a unique file hash.
Despite the differences mentioned above, CIS CTI is almost certain that all four variants belong to the same campaign based on consistent shared indicators that no opportunistic overlap would explain.
- First, the PowerShell source code is functionally identical across all variants, with the same core commands (
run,openTab,launchChrome), initialization JSON structure with empty Telegram fields, 20-second keepalive beacon, and reconnect logic. The only differences across Variants 1–3 are the embedded hardcoded C2 IP address and a single comment header, while Variant 4 retains the same RAT core but adds anelevatecommand and a version marker. - Second, Variants 1, 3, and 4 use Cloudzy (formerly Router Hosting) AS14956 infrastructure with their IP allocations overlapping within the
172.86.0[.]0/16block, while Variant 2 uses a separate, non-Cloudzy IP address. - Third, all eight CTA-controlled GCS buckets identified used by Variants 1, 2, and 4 follow an identical [adjective]-[nature-noun]-[4-digit-number] naming convention (for example
tall-marsh-1820,keen-creek-8808,deep-beach-5841,glad-delta-7225), which is notable because GCS bucket names are user-chosen globally unique strings. Variant 3 does not use GCS; rather, its payload is embedded directly in the VBS dropper. - Most significantly, the C2 servers of Variants 1–3 all return a byte-for-byte identical operator panel (detailed under Campaign Infrastructure). Identical operator-facing infrastructure deployed across three otherwise-independent C2 clusters is materially harder to explain through coincidental code reuse than shared RAT code alone.
Analysis of the Killchain
The MS-ISAC member’s independent analysis included detonating each email and payload in a controlled sandbox environment. Following this, the member provided the CIS CTI team with both phishing MSG files, PowerShell RAT logs, and recovered binaries for further analysis. The technical analysis that follows describes Variant 1’s kill chain from initial phishing email to dual-RMM deployment observed end to end across both detonations and across recovered samples.
Phishing Emails: Abuse of Google Drive Share Notifications
The phishing emails are delivered as Google Drive share notifications originating from a legitimate Google mail server (drive-shares-noreply@google[.]com), as shown in Figure 1. As a result, the phishing emails carry a valid Google Domain Key Identified Mail (DKIM) signature and pass sender policy framework (SPF) and Domain-based Message Authentication, Reporting and Conformance (DMARC) authentication checks.
The CTA created Google accounts under two domains they controlled, safeandtrustedconnections[.]com and instantotification[.]com, with the latter being a typosquat of the legitimate instantnotification[.]com. Both phishing lures impersonate a law firm, with one citing a compliance failure with a deadline and the other a balance increase requiring immediate action. The subject lines and impersonated law firm display names use Unicode homoglyph substitution, Cyrillic and Greek characters visually indistinguishable from Latin letters, to evade email gateway keyword matching.

Figure 1: Google Drive share phishing email
Phishing Emails: Client-Side Dropper Assembly
Once a victim clicks the Google Drive link, a webpage displaying a fake DocuSign PDF presents a download button. (See Figure 2.)

Figure 2: Fake DocuSign PDF
Clicking it opened a second tab to a GCS hosted HTML lure page that immediately generates and downloads a Visual Basic Script (VBS) dropper. (See Figure 3.) The VBS dropper is not a static file on the server. Instead, JavaScript on the lure page fetches the PowerShell RAT live from a separate GCS staging bucket before assembling the full two-stage dropper entirely in the victim’s browser and delivering it to the victim as an in-browser file download. This allows the CTAs to rotate C2 IPs by updating only the PowerShell RAT in the staging bucket without modifying any other infrastructure components.

Figure 3: GCS-hosted HTML lure page, which immediately generates and downloads a Visual Basic Script (VBS) dropper
VBS Dropper and Embedded PowerShell RAT delivery
The VBS dropper downloaded to the victim’s machine is a three-line wrapper whose sole function is to invoke powershell.exe with a UTF-16LE Base64 encoded command via -EncodedCommand. It uses ShellExecute with runas to request UAC elevation and a hidden window, as shown in Figure 4. The full PowerShell RAT is embedded inside the VBS as a second Base64 layer, requiring no external download for RAT delivery. This embedded delivery technique is a defense evasion technique, as fewer network dependencies mean fewer opportunities for detection at the network layer.

Figure 4: VBS dropper PowerShell invocation (excerpt). The full PowerShell RAT is embedded as a second Base64 layer inside the -EncodedCommand UTF-16LE string
Once decoded, the initial PowerShell writes the PowerShell RAT, named agent.ps1, to %APPDATA%\TelegramTabOpener\native-host\agent.ps1, a deliberate camouflage path given the RAT has no actual Telegram functionality.
PowerShell WebSocket RAT
The two member-submitted PowerShell RATs analyzed by CIS CTI are identical to each other except for the embedded C2 IP addresses, ws://45.61.163[.]253:3000 and ws://172.86.108[.]91:3000, with both resolving to Cloudzy AS14956 infrastructure. WebSocket gives the operator a persistent, full-duplex channel for real-time, hands-on-keyboard interaction, per RFC Editor. Many enterprise proxies do not inspect WebSocket traffic beyond the initial HTTP upgrade handshake, notes OWASP Cheat Sheet Series, allowing the C2 channel to evade further inspection.
The WebSocket transport is unencrypted because the RAT is only used to issue three commands before the RMM tools establish persistent access:
- The
runcommand executes operator-supplied commands viacmd.exeorPowerShell.exeand returns their output openTabopens an operator-supplied URL in the victim’s default browserlaunchChromelaunches Chrome across user profiles.
Together, openTab and launchChrome give the operator control of the victim’s already-authenticated browser session, which is consistent with the browser-driven financial-platform enumeration Proofpoint documented for the same actor.
Persistence and C2
The RAT establishes two layers of persistence.
- The primary layer is a scheduled task named
TabOpenerAgentthat runs as SYSTEM with the highest privileges and triggers at both startup and user logon. - The secondary layer is a registry Run key named
GoogleChromeAutoStart, a fallback if the scheduled task is removed.
With persistence in place, the RAT opens an unencrypted WebSocket connection to the CTAs C2 on port 3000, sends a JSON payload identifying the victim’s hostname, and enters an infinite reconnect loop with a 20-second keepalive.
Dual-RMM Deployment
In the final observed stage, the operator issues commands through the RAT to download and silently install ScreenConnect (mg.msi) and Pulseway (windows_agent_x64.msi). Both installers are downloaded from CTA-controlled GCS buckets and installed via msiexec /quiet /qn. The threat actor disabled the SSL certificate revocation checking via --ssl-no-revoke curl flag likely due to ScreenConnect certificates being revoked in related campaigns.
Both RMMs establish independent, persistent remote access channels beyond the PowerShell RAT.
Payload Analysis
The main payloads in this campaign are the two RMM installers, ScreenConnect and Pulseway. Both are unmodified, legitimately signed software that pass standard AV and EDR signature checks.
The ScreenConnect (ConnectWise) client is configured for covert unattended access with all notifications disabled and its C2 set to mgnajgk2.anondns[.]net:8041; its Client_Override resources rebrand it as “Session” with a generic green shield icon.
The Pulseway client enrolls to the CTA tenant thehealingpc.pulseway.com, likely masquerading as a PC-repair or IT-support business. Notably, the Pulseway installer is an exact SHA256 hash match for the payload Proofpoint Threat Research documented in the February–March 2026 cargo theft and freight fraud campaign.
Join the MS-ISAC to Strengthen Your Phishing Defenses
The CIS CTI team recommends U.S. SLTTs join the MS-ISAC, a community dedicated to the Collective Cyber Defense of U.S. SLTTs. MS-ISAC members received early reporting on this malware campaign, including over 100 indicators of compromise (IOCs) disseminated through our Indicator Sharing Program. Additionally, members can take advantage of proactive web security through the MDBR service. Finally, the CIS CTI team provided membership with a more detailed report on this campaign, including IOCs and recommendations. This information is intended to provide actionable threat intelligence that directly supports proactive Collective Cyber Defense in the U.S. SLTT community along with informed decision making.
Ready to help your organization stay safe against threats like PowerShell WebSocket RATs?
