Blackpoint SOC Threat Pulse: Week of July 27, 2026

In this week’s Threat Pulse, the Blackpoint Security Operations Center breaks down a ClickFix-style attack that led to an in-memory RAT deployment, where a user was tricked into running a PowerShell command that suppressed security telemetry, established COM hijack persistence, and loaded a variant of Overlord RAT, dubbed SpaceX1337, directly into memory to avoid detection. Plus, the Adversary Pursuit Group (APG) is tracking a separate but related cluster of ClickFix activity using a Python-based RAT that resolves its command-and-control infrastructure through an Ethereum smart contract, and a critical, actively exploited vulnerability in Check Point SmartConsole now sits on CISA’s Known Exploited Vulnerabilities list.

Executive Summary

  • A ClickFix-style social engineering lure convinced a user to run a malicious PowerShell command, which retrieved and executed a second-stage script from attacker infrastructure.
  • Weekly snapshot: over 115 incidents observed, with 87% disrupted before a payload could be deployed, reinforcing that early behavioral detection is stopping the majority of attacks before they matter.
  • Separately, the Blackpoint APG is tracking a related but distinct ClickFix cluster using a Python-based RAT with Ethereum smart contract-based C2, five instances of which were stopped by the SOC in the past 7 days before any payload delivery.
  • The Blackpoint APG also issued a threat notice this week on an actively exploited, CVSS 9.1 authentication bypass vulnerability in Check Point SmartConsole (CVE-2026-16232), now on CISA’s Known Exploited Vulnerabilities catalog.
  • Bottom line: ClickFix remains the dominant initial access technique of 2026 because it targets people, not software, and the payloads behind it are getting stealthier, living in memory rather than on disk. Fast isolation and full attack-chain analysis are what turn these incidents into non-events.

Houston, We Have a RAT Problem

What we’re seeing

  • The Blackpoint SOC alerted to suspicious powershell.exe activity; further analysis identified this was the result of a ClickFix-style attack.
  • The command retrieved and executed a second-stage PowerShell script from attacker infrastructure, dropping a file in the user’s temp directory.
  • The script suppressed AMSI and PowerShell telemetry and established persistence through hidden files and a COM hijack registry configuration.
  • It downloaded an AES-encrypted payload and manually mapped it directly into memory, bypassing normal process creation.
  • The payload was identified as a variant of Overlord RAT, dubbed SpaceX1337, an open-source remote access trojan with credential theft, cryptocurrency theft, and HVNC capabilities.

What the Blackpoint SOC did

  • Isolated the affected host immediately and confirmed no lateral movement to other hosts on the network.
  • Conducted deep-dive analysis to fully reverse and document the loader, persistence mechanisms, and final payload.

Why this matters

  • This is exactly the kind of stealthy attack that routinely evades traditional antivirus, the Blackpoint SOC successfully identified and contained the threat before any further malicious activity could occur.

BROC Weekly Snapshot

What changed. What didn’t. What matters.

Incidents Observed
>115↑
Pre-Payload Disruptions
87%
Pre-Ransom Interruptions
2%

Campaign Statuses

Fake CAPTCHA/ClickFix Ongoing 32%
Rogue RMM Ongoing 29%
Fake Updates Escalating 9%
Trojanized Installers Ongoing 4%
SSL VPN Compromise Ongoing 3%

Quick Take

The Blackpoint APG has been tracking a cluster of activity, which begins with a ClickFix-style attack. The executed command utilizes PowerShell to execute Python-based remote access trojan (RAT). Once running, the malware fingerprints the host, checks the local language, and establishes persistence via scheduled tasks. Unlike other ClickFix clusters we have observed, the command and control in this case uses an Ethereum smart contract to resolve its active infrastructure.

The Blackpoint SOC has responded to five of these incidents over the previous 7 days, stopping the activity before a final payload could be delivered in all cases. Additional analysis by the Blackpoint APG team identified the difference in C2 design and supported by external research, the potential payload delivery.

ClickFix continues to be the most frequently observed initial access vector in 2026. The technique has been widely adopted by malware-as-a-service (MaaS) and ransomware-as-a-service (RaaS) operations, other financially motivated cybercriminals, and nation-state threat actors. Its widespread adoption is very likely driven by its effectiveness as a low-cost, socially engineered access technique. As ClickFix becomes increasingly common across the threat landscape, it also becomes more difficult to attribute activity based on the initial access method alone, reinforcing the need for intelligence-driven defensive measures.

DATE PUBLISHEDJuly 28, 2026
AUTHORAndi Ursry

The 2AM Test

Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours

GET YOUR COPY