A financially motivated cargo-theft and freight-fraud operation has expanded to U.S. state, local, tribal, and territorial government networks through phishing emails impersonating legitimate Google Drive sharing notifications. The campaign delivers a custom PowerShell WebSocket remote-access trojan (RAT), giving operators interactive access before deploying both ConnectWise ScreenConnect and Pulseway remote monitoring and management (RMM) tools for redundant persistence.
Attackers host lures and payloads in Google Cloud Storage, use Unicode homoglyphs to disguise content, and generate VBS droppers in the victim’s browser to evade security controls. CIS linked the activity to the cargo-theft campaign documented by Proofpoint through an identical Pulseway installer hash as well as overlapping infrastructure and tradecraft; observed variants include encrypted WebSocket command-and-control, UAC-bypass capabilities, and randomized payload builds, while beacons from additional government networks indicate continued expansion beyond transportation and logistics victims.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
CIS analyzed four delivery variants that used VBS or MSI-based droppers, in-memory RAT execution, scheduled-task persistence, and subsequent deployment of ScreenConnect and Pulseway. The newest variant added encrypted WebSocket C2, a COM elevation-moniker UAC bypass, multistage Google Cloud Storage retrieval, and randomized payload components.
CIS identified connections to confirmed campaign infrastructure from multiple additional SLTT member networks through Albert Network Monitoring and Management sensor data and MDBR data. It assessed that the operators were broadening beyond transportation and logistics targets.
CIS assessed with near certainty that the SLTT phishing activity was a new wave of the cargo-theft and freight-fraud operation previously reported by Proofpoint. The assessment was supported by an exact Pulseway installer SHA-256 match and overlapping infrastructure, delivery methods, and dual-RMM tradecraft.
CIS identified an active phishing campaign targeting multiple U.S. state, local, tribal, and territorial government networks. The campaign used Google Drive-sharing notifications and Google Cloud Storage-hosted lures to deliver a custom PowerShell WebSocket RAT, followed by ScreenConnect and Pulseway for persistent access.
Proofpoint Threat Research documented a financially motivated campaign involving cargo theft and freight fraud during February and March 2026. The operators were observed seeking access to banking portals, payment platforms, and accounting software after establishing persistence.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.