INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
SLTTs Hit by Dual-RMM Phishing and PowerShell RAT Campaign
| 2026-08-31 05:55 MALWARE & BOTNETS PHISHING & SOCIAL ENGINEERING
Executive Summary
AI-generated
An active phishing campaign targeting the transportation and logistics sector in the United States, likely to extend beyond its initial target, has been identified by the Center for Internet Security (CIS). The attackers are using malware families including JSON, WebSocket, PowerShell RAT, VBS, as well as tactics such as spear-phishing lures with regionally tailored Office documents. This campaign is affecting approximately 5 government organizations across Central Asia, which were targeted by an advanced persistent threat group called SilkParasite in late 2025. The attackers are using a collection of mostly previously unidentified remote access Trojans (RATs) from seven different malware families to establish and maintain long-term access to selected victims.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ww•••••.com
sa•••••.com
si•••••.co
mg•••••.net
hxxp://••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Incident Timeline
Intelligence Sources
Dark Reading
2026-08-19
AlienVault OTX
2026-09-03
AlienVault OTX
2026-08-31