Notes from the Chief Security and Trust Officer: September 2026

September gave us a pretty good look at where attacker tradecraft is headed.

ClickFix is still everywhere. Rogue RMM isn’t slowing down. APG watched malware rotate its command and control infrastructure through blockchain smart contracts in real time.

RMMProject: The September Threat Worth Watching

But the one I keep coming back to showed up the week of September 7th, when APG investigated RMMProject, a modular RAT capable of browser credential theft, VNC access, and network proxying. It arrived through a trojanized cryptocurrency wallet delivered as a double-extension file made to look like an insurance document and injected directly into memory. The SOC isolated it before the loader could reach out for tasking.

That’s the one worth paying attention to.

AI-Managed Exploitation in the Wild

We also found something else this month that’s stuck with me: an exposed attacker workspace showing AI being used to manage an exploitation campaign across hundreds of systems.

The campaign targeted two PaperCut vulnerabilities, CVE-2026-81578 and CVE-2026-82078. APG found the project files sitting in an exposed HTTP directory on operator infrastructure, including timestamped state files, country exclusion lists, failure logs, and retry logic configured for 200 concurrent threads and as many as 100 rounds.

None of those pieces is particularly novel by itself. What matters is how they were being used together. AI was keeping track of what had already run, what failed, and what should happen next, allowing the campaign to keep moving without someone manually managing every step.

Patch the PaperCut vulnerabilities. But if you have an internet-facing PaperCut server and aren’t sure whether it was hit, don’t stop there. The campaign was built to move from initial exploitation into privileged access, Active Directory collection, credential harvesting, and proxy setup. Treat that as a network intrusion and scope accordingly.

Blackpoint: Platform and Trust

We shipped nine new ITDR detections in September that matter for our partners and customers.

First, we continued to address device code phishing, which is tricky because the authentication itself goes through Microsoft’s legitimate flow. Without detection built specifically around the technique, the resulting sign-in can look perfectly normal in the logs.

We also added two Microsoft Teams detections covering helpdesk impersonation and tenant name spoofing. Teams is increasingly part of the attack surface because people trust it. A message that looks like it came from IT inside an internal collaboration tool tends to get treated very differently than the same request arriving through email.

The other six detections cover suspicious sending patterns, anomalous tokens, attacker-in-the-middle activity, possible PRT access, verified threat actor IPs, and suspicious browser sign-ins.

Response got faster too. Geo and VPN Policy Automation can now block logins from unapproved countries or commercial VPNs as they happen and push that policy across every managed tenant at once.

For Google Workspace, Auto Logout gives the SOC another option when an account is compromised: terminate the session and reset the password without disabling the account and potentially losing mailbox or calendar data.

21 Seconds: September’s Fastest Containment

Our fastest containment in September was 21 seconds. Average containment remains under two minutes.

The ITDR historical scan now looks back as far as 180 days when a Microsoft 365 tenant is onboarded. That’s important because monitoring shouldn’t begin with the assumption that the environment was clean when we got there.

A few other platform updates worth knowing: User-Level VPN Policies are now generally available, Cloud Posture can send webhook and email notifications when policies or baselines change, and partners can request archived SIEM logs going back as far as a year from the SIEM Log page, with retrieval available within 48 hours.

We’re also bringing a customer-facing roadmap into CompassOne. We gave partners an early look during the CompassOne: Past, Present, and Future webinar on September 29th.

The SOC: Stopping It in Real Time

ClickFix Is Still the Story

Through mid-September, the SOC had responded to more than 470 confirmed ClickFix style incidents over the previous 90 days, accounting for roughly a third of confirmed incidents. More than 85% were interrupted before an initial payload was executed.

We’ve been talking about ClickFix all year, but the important change is who is using it. What started as a technique heavily associated with financially motivated activity is now showing up across malware-as-a-service and ransomware operations as well as nation state activity.

At this point, seeing ClickFix tells you how someone got in. It doesn’t necessarily tell you who they are.

The incidents themselves keep changing.

As highlighted above, the newest development came during the week of September 7th with RMMProject, where the SOC stopped a memory-injected modular RAT before its loader could reach out for tasking.

During the week of September 21st, a ClickFix chain downloaded a ZIP archive, extracted and hid the folder, created persistence through a registry Run key, and reconstructed Lorem Ipsum associated shellcode directly in memory.

The shellcode used a public WebMasterSun profile as a dead drop resolver before communicating through victim specific BMP tasking. The final payload was disguised as legitimate AWS disaster recovery software.

A week earlier, we saw rogue Quick Assist paired with ClickFix style social engineering through the Windows Run dialog. The attacker used it to install a backup application from attacker controlled infrastructure. The SOC isolated the host and cut off access before the attacker could move further.

Rogue RMM activity accounted for roughly a third of incidents in each of September’s weekly snapshots. Trojanized installer incidents had also jumped 85% from July to August, driven largely by rogue ScreenConnect deployments.

Different lure. Different payload. Same basic problem. Attackers are getting very good at abusing tools and workflows people already recognize and trust.

Cisco ISE CVE-2026-76460 Needs Attention

One vulnerability also deserves attention. Cisco ISE and ISE-PIC CVE-2026-76460 carries a CVSS score of 10 and was added to CISA’s Known Exploited Vulnerabilities catalog on September 16th.

An unauthenticated attacker can send a crafted request to an affected API endpoint and achieve root-level command execution through the web management interface.

There is no vendor workaround beyond restricting access to the management plane, so patching needs to be the priority.

APG: The Research Behind the Reflex

APG had another busy month, but ChainScript is probably the best example of why we spend so much time looking beyond individual indicators.

ChainScript is a Node.js remote access trojan APG identified while investigating ClickFix activity. We found it inside malicious MSI packages masquerading as Spotify, Zoom Workplace, and Microsoft Teams.

It bundles its own Node.js runtime, establishes persistence through a scheduled task with a Run key as backup, and then does something more interesting for command and control.

It asks the blockchain where to connect.

Instead of hardcoding one command and control server into the malware, ChainScript queries a Polygon smart contract at runtime for the current WebSocket panel address.

APG watched that process happen during live protocol analysis. One session resolved to shift-api-control[.]com on port 3847. After the connection reset, the same implant queried the same contract again and got bedotiq[.]net on port 3854.

No new implant. No rebuild. The operator changed the backend and kept moving.

ChainScript wasn’t the only one. APG tracked two other RATs during September, one Python based and another written in Node.js, that also used Ethereum smart contracts to resolve command and control infrastructure.

That creates a fairly obvious problem if your detection strategy depends heavily on static domains and IP addresses. The infrastructure can change faster than those indicators can be operationalized.

The host behavior is harder to hide.

What the PaperCut Workspace Tells Us About AI

And that brings me back to the PaperCut workspace we found this month.

The individual techniques in those files weren’t exotic: vulnerability research, target filtering, retries, failure classification. What caught my attention was the state management between them.

The workflow remembered what it had done, separated different types of failures, adjusted when real environments didn’t behave as expected, and retried what was worth retrying.

We’ve talked a lot about AI making attackers faster. This is a better example of what that can actually mean in practice. It isn’t necessarily a new exploit or some magic AI-generated technique. It’s taking work that used to require an operator to sit between stages and handing more of that coordination to the system itself.

That’s a much more practical change, and I think it’s one defenders need to understand.

What This Adds Up To

There were a lot of individual stories in September, but they point in roughly the same direction.

Identity attacks are taking advantage of legitimate authentication and collaboration workflows, so we added nine ITDR detections and pushed more response into automation. ClickFix remained the dominant initial access technique we saw, even as the actors and payloads behind it kept changing. APG watched malware rotate infrastructure through blockchain resolvers and found an exploitation workflow using AI to maintain state and keep a campaign moving.

Attackers are building operations that are easier to change and harder to disrupt by pulling one indicator.

So we have to detect what doesn’t change with them.

  • A scheduled task appearing where it shouldn’t.
  • A PaperCut service spawning discovery tooling.
  • A bundled Node.js runtime suddenly making outbound connections.
  • Strange process lineage after a user runs something from the Windows Run dialog.

Domains rotate. IPs disappear. Payload names change.

Behavior gives you something more durable to hunt.

See you next month.

Wil

DATE PUBLISHEDOctober 2, 2026
AUTHORBlackpoint Cyber

The 2AM Test

Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours

GET YOUR COPY