Blackpoint SOC Threat Pulse: Week of August 3, 2026

In this week’s Threat Pulse, the Blackpoint Security Operations Center unravels a USB-borne worm that used disguised shortcut files to trick users into re-launching malware previously tied to ransomware deployment. Plus, the Adversary Pursuit Group (APG) and SOC uncover a coordinated phishing campaign targeting healthcare organizations, using Discord CDN and Cloudflare Workers infrastructure across multiple customers, and two Cisco Secure Firewall Management Center vulnerabilities are added to the watch list, including one rated a perfect 10.0 CVSS. 

Executive Summary

  • The Blackpoint SOC identified an AutoIt-based worm spreading via connected USB storage devices, using disguised shortcut (.lnk) files that mimic common folders like Pictures and Music to trick users into re-launching the malware. 
  • The worm staged a renamed AutoIt3.exe executable and a malicious compiled script in a hidden folder, a family previously reported to deploy ransomware once fully executed. 
  • The Blackpoint SOC isolated the affected device immediately and confirmed no lateral movement to other hosts, stopping the infection before any payload could deploy. 
  • Weekly snapshot: over 105 incidents observed, with 89% disrupted before payload deployment, showing continued strength in catching threats at the earliest stage. 
  • Separately, the Blackpoint APG and SOC identified a coordinated phishing campaign targeting healthcare organizations, using malicious Outlook emails, Discord CDN-hosted JavaScript, and Cloudflare Workers for command-and-control, with 100% of these incidents interrupted before a final payload landed. 
  • The Blackpoint APG also issued threat notices this week on two Cisco Secure Firewall Management Center (FMC) vulnerabilities: a static credential exposure (CVE-2026-20316, CVSS 5.3) already confirmed under active exploitation, and a maximum-severity authentication bypass (CVE-2026-20079, CVSS 10.0) that has not yet been confirmed as exploited. 
  • Bottom line: This week’s activity shows attackers working every angle, physical media, email, and unpatched infrastructure, but the pattern holds: early behavioral detection is stopping the overwhelming majority of these attacks before real damage occurs. 

Plugged, Not Played  

What we’re seeing

  • The Blackpoint SOC responded to an alert involving suspicious a3x execution, further analysis determine the initial access was likely a USB device.  
  • Further investigation identified a renamed AutoIt3.exe executable running a malicious compiled AutoIt script, both staged in a hidden folder alongside additional worm components. 
  •  Fake shortcut (.lnk) files disguised as common folders (Pictures, Music, Reports, etc.) were found in the same location, designed to trick the user into re-launching the malware. 
  • The malware was identified as an AutoIt-based worm designed to spread via connected USB storage devices and previously reported to deploy ransomware. 

What the Blackpoint SOC did

  • The Blackpoint SOC isolated the device immediately and confirmed no lateral movement to other hosts.  

Why this matters

  • USB worms spread through removable media and disguised shortcuts rather than the network, an infection vector traditional defenses often miss; this activity was identified and isolated by the Blackpoint SOC before further malicious activity, like ransomware deployment, could occur.  

BROC Weekly Snapshot

What changed. What didn’t. What matters.

Campaign Statuses 

Fake CAPTCHA/ClickFix   Ongoing  28% 
Rogue RMM    Ongoing   18% 
SSL VPN Compromise   Ongoing   6% 
Trojanized Installers   Ongoing 1% 
Fake Updates   Ongoing   1% 

Quick Take 

The Blackpoint APG and SOC has identified a phishing campaign targeting healthcare organizations across multiple incidents, in which users received malicious emails via Outlook that spawned Chrome processes redirecting to Discord CDN-hosted JavaScript files. The consistent use of Discord CDN for staging, wscript.exe for execution, and Cloudflare Workers for C2 activity across multiple customers and dates indicates a coordinated campaign.  

The Blackpoint SOC has interrupted 100% of these incidents before a final payload could be delivered. Additional analysis by the Blackpoint APG team has identified rotating Malware-as-a-Service payloads, with PhantomStealer and FormBook identified as attempted final-stage malware to date. 

DATE PUBLISHEDAugust 4, 2026
AUTHORAndi Ursry

The 2AM Test

Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours

GET YOUR COPY