Blackpoint SOC Threat Pulse: Week of August 10, 2026
In this week’s Threat Pulse, the Blackpoint Security Operations Center (SOC) uncovers an attacker weaponizing trusted remote monitoring and management (RMM) tools, deploying an unauthorized ScreenConnect instance disguised as a fake Adobe PDF installer, then hiding it from the Windows Control Panel to maintain persistent, full-privilege access. Plus, the Adversary Pursuit Group (APG) breaks down why SSL VPN appliances remain a top target for ransomware operators, and two actively exploited authentication bypass vulnerabilities in N-able N-central land on CISA’s Known Exploited Vulnerabilities list.
Executive Summary
- A user was tricked into running a fake Adobe PDF installer that chained two unauthorized RMM tools together, ultimately deploying a hidden ScreenConnect instance with full system-level, persistent remote access.
- The Blackpoint SOC isolated the compromised host immediately, preventing lateral movement, and fully documented the attacker’s tools and infrastructure to support remediation.
- Weekly snapshot: over 125 incidents observed, with 91% disrupted before payload deployment, both up from the prior week, additionally, 5% of incidents last week were identified as likely pre-ransomware activity.
- The Blackpoint APG tracks SSL VPN appliances as a persistently high value target: nearly 30 incidents in the past 30 days, all shut down before payload delivery, spanning Professional & Commercial Services, Industrials, and Institutions & Organizations.
- The Blackpoint APG issued a threat notice this week on two actively exploited authentication bypass vulnerabilities in N-able N-central (CVE-2026-18556 and CVE-2026-18577, both CVSS 8.2), the second stemming from an incomplete patch for the first, both added to the CISA KEV catalog.
- Bottom line: Attackers are increasingly hiding inside the legitimate tools organizations already trust, RMM software and VPN appliances alike, making behavior-based detection and rapid isolation essential to catching intrusions that would otherwise blend in for days.
Featured Incident
ScreenConnect the Dots
What we’re seeing
- The Blackpoint SOC responded to an alert for a malicious ScreenConnect detection; initial access was identified as a file masquerading as a legitimate Adobe PDF Installer.
- The unauthorized RMM agent, Bluetrait, used PowerShell to install a second, unauthorized remote access tool and connect to attacker-controlled infrastructure.
- The rogue ScreenConnect instance concealed itself from the Windows Control Panel to evade detection and modified power settings to keep the machine awake and accessible.
- The attacker established persistent remote access with full system-level privileges, enabling command execution on the compromised endpoint.
What the Blackpoint SOC did
- The Blackpoint SOC immediately isolated the compromised host, cutting off attacker access before lateral movement could occur.
- SOC analysts identified and documented all rogue tools, malicious domains, and attacker infrastructure to support full remediation.
Why this matters
- Attackers are weaponizing trusted RMM tools to bypass traditional antivirus. Without 24/7 SOC monitoring and rapid isolation, this type of stealthy intrusion can go undetected for days, giving threat actors unrestricted access to an organization’s systems and data.
BROC Weekly Snapshot
What changed. What didn’t. What matters.
Campaign Statuses
| Fake CAPTCHA/ClickFix | ↑ | Ongoing | 29% |
| Rogue RMM | ↑ | Ongoing | 20% |
| SSL VPN Compromise | ↑ | Ongoing | 10% |
| Trojanized Installers | ↑ | Ongoing | 4% |
| Fake Updates | ↑ | Ongoing | 3% |
Quick Take
The Blackpoint APG tracks the targeting of prioritized software, which are tools that are widely deployed, frequently targeted, and present a high risk if exploited. One of these categories includes SSL VPNs due to the frequent targeting of these appliances. SSL VPN appliances are often internet-facing, provide direct access to internal networks, and are frequently targeted through exploited vulnerabilities and compromised credentials.
Over the previous 30 days, the Blackpoint SOC has responded to nearly 30 incidents involving SSL VPN appliances. 100% of these were shut down before payloads or further malicious action could occur. The most frequently targeted industries within this category of tracking include Professional & Commercial Services, Industrials, and Institutions & Organizations highlighting the wide range of opportunistic targeting by threat actors. It is very likely that the Blackpoint SOC will continue to observe this trend throughout the rest of 2026; SSL VPN appliances have been reported to be targeted by multiple ransomware operations including Akira, INC Ransom, The Gentlemen, and more.
DATE PUBLISHEDAugust 12, 2026
AUTHORAndi Ursry
SHARE ON
The 2AM Test
Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours