Bottom line: U.S. SLTTs are being targeted with custom malware, increasing risk exposure.
What's happening: The phishing campaigns are using a custom PowerShell WebSocket RAT and dual RMM tools, such as Malwarebytes 4.11.3.2300, and exploiting vulnerabilities in Windows Server 2019 (CVE-2021-34417) and Windows Server 2016 (CVE-2021-4465).
What to do: Security leaders should monitor threat actor activity and ensure their SLTTs have up-to-date antivirus software, such as Norton 22.10.5.123, and implement endpoint protection with tools like CrowdStrike Falcon.