Blackpoint SOC Threat Pulse: Week of July 20, 2026

In this week’s Threat Pulse, the Blackpoint Security Operations Center (SOC) uncovers a multi-stage attack where threat actors disguised malware as a legitimate software download, then used a fake Microsoft Edge update task to silently establish persistence — hiding inside normal Windows processes the entire time. Plus, the Adversary Pursuit Group (APG) takes stock of the first half of 2026: over 1,900 incidents observed, and the same three attack campaigns that dominated 2025 are still leading the charge — because they keep working.

Executive Summary

  • Attackers used a fake software download to plant hidden malware that disguised itself as a routine Microsoft Edge update task.
  • The malware abused legitimate Windows processes (a technique known as “living off the land”) to blend in with normal system activity and attempt to establish remote communication back to the attacker’s infrastructure via STX RAT.
  • The Blackpoint SOC detected the unusual behavior, immediately isolated the affected device, and confirmed no spread to other systems, stopping a potential full network compromise at the earliest possible stage.
  • First-half of 2026 data from the Blackpoint SOC shows over 1,900 incidents observed, with more than 67% disrupted before any malicious payload was deployed, a direct result of round-the-clock human-led monitoring.
  • The same three attack campaigns leading in 2025 (ClickFix/Fake CAPTCHA, Rogue RMM, and SSL VPN Compromise) continue to dominate in 2026, signaling that threat actors are doubling down on tactics that still work against organizations without 24/7 coverage.
  • Bottom line: Sophisticated attacks are actively targeting businesses through trusted-looking software and built-in system tools.

What we’re seeing

  • The Blackpoint SOC alerted to malicious regsvr32.exe activity that led to a hidden PowerShell loader downloading a payload disguised as a PNG and executing it via regsvr32.exe, behavior inconsistent with legitimate Windows activity.
  • A scheduled task masquerading as a Microsoft Edge Update task repeatedly executed the disguised DLL using regsvr32.exe.
  • The PowerShell loader decoded and executed an in-memory payload that attempted outbound command-and-control communications, including infrastructure associated with STX RAT.

What the Blackpoint SOC did

  • Isolated the affected host immediately to prevent further malicious activity and confirmed no lateral movement to other hosts.
  • Conducted further analysis to confirm the full attack chain, including the trojanized installer, PowerShell loader, LOLBin abuse via regsvr32.exe, and STX RAT.

Why this matters

  • This attack relied on a trojanized software download and living-off-the-land binary abuse to blend in with legitimate Windows processes, which routinely evades traditional security tooling. The Blackpoint SOC identified the activity before the STX RAT could make C2 connections successful or gain further access.

BROC Weekly Snapshot

What changed. What didn’t. What matters.

Incidents Observed
>95↓
Pre-Payload Disruptions
88%↑
Pre-Ransom Interruptions
2%↓


Campaign Statuses

Fake CAPTCHA/ClickFix Ongoing 34%
Rogue RMM Escalating 27%
Trojanized Installers Ongoing 4%
SSL VPN Compromise Ongoing 2%

Quick Take

The first half of 2026 brought a flurry of activity for the Blackpoint SOC, with more than 1,900 incidents. Of those, more than 67% were disrupted prior to anything being deployed and before there were artifacts that could be gathered to identify what payload may have been deployed.

The most frequently observed campaign has been Fake CAPTCHA/ClickFix, increasing activity from 2025, followed by rogue RMM tools and SSL VPN compromise. These three campaigns were also the most frequently observed in 2025, indicating threat actors continue to rely on the tried-and-true tactics for initial access. 

DATE PUBLISHEDJuly 21, 2026
AUTHORBlackpoint Cyber

Blackpoint AI: A Decade in the Making

Webinar - July 22
Automated attacks need automated defense. Learn how Blackpoint AI protects your clients from identity threats by containing threats in as little as 21 seconds.*
*Under two minutes on average

REGISTER NOW