cisastandardsNewsThe Broadside2 min read

PowerShell RAT and Dual RMM Tools Target SLTT Governments

Dual RMM persistence favors redundancy over evasion, targeting the monitoring gaps that leave SLTT IT teams blind to a second backdoor when they miss the first.


TL;DR

CIS CTI identified an active phishing campaign targeting U.S. SLTT governments with a custom PowerShell WebSocket RAT and dual remote monitoring and management tools for persistence. The adversary chains a PowerShell backdoor with two separate RMM installations, betting that under-resourced government IT teams won't detect all three. The dual-RMM approach echoes CISA's 2023 advisory on malicious RMM use, but the deliberate redundancy signals an adversary who expects endpoint monitoring gaps and builds around them.

CIS's Cyber Threat Intelligence team has identified an active phishing campaign targeting U.S. state, local, tribal, and territorial governments with a custom PowerShell WebSocket-based remote access trojan and two separate remote monitoring and management tools deployed for persistence. The PowerShell RAT provides WebSocket command and control; the dual RMM installations supply redundant backdoors for lateral movement.

The dual-RMM approach is the operational signal. One RMM tool for persistence is a known tactic: CISA, NSA, and MS-ISAC jointly warned about it in a January 2023 advisory that flagged ScreenConnect and AnyDesk used as backdoors after phishing-based initial access. Two RMM tools plus a custom RAT says the adversary isn't optimizing for stealth; it's optimizing for reliability. If the victim's IT staff finds and removes one persistence mechanism, the other two remain. Against SLTT environments where endpoint monitoring runs during business hours or is outsourced to an MSP with dozens of other clients, that redundancy is cheap insurance. CIS hasn't disclosed which specific RMM tools are being deployed, whether this campaign is attributed to a known threat actor, or how many organizations have been successfully compromised.

The campaign fits a pattern. In March 2026, CIS CTI documented the ZPHP campaign, which used fake CAPTCHA pages and the ClickFix technique to drop the Remcos RAT on SLTT endpoints. Earlier, an IRS-themed phishing wave pushed legitimate RemotePC software through TryCloudflare-tunneled domains onto government machines. The common thread across all three campaigns is commodity techniques and legitimate tools aimed at under-resourced defenders. What distinguishes this one is the layering: a custom RAT backed by two separate RMM persistence channels.

For SLTT IT teams and the MSPs that support them, the immediate priority is hunting unauthorized RMM installations across the endpoint fleet. Application allowlisting should block portable RMM executables that haven't been explicitly approved. CISA's 2023 advisory includes detection guidance and IOC formats that remain directly applicable. The adversary's bet is that defenders will catch something, just not everything. That bet has to be met with monitoring coverage that proves it wrong.


Published ·Deep Fathom