Blackpoint SOC Threat Pulse: Week of August 24, 2026

In this week’s Threat Pulse, the Blackpoint Security Operations Center (SOC) uncovers an attacker disguising a malicious payload as a security certificate, using echo commands to write out a fake PEM-formatted X.509 file and a trusted Windows utility to decode it, all in service of silently installing a rogue ScreenConnect client. Additionally, the Blackpoint Adversary Pursuit Group (APG) continues to track the evolving Avalon malware framework, which shows signs of AI-assisted development and carries a built-in ransom capability.

Cert-ifiably Malicious 

What we’re seeing 

  • The Blackpoint SOC alerted to a suspiciously named LNK file executing on a host after a user opened a financially themed lure delivered inside a downloaded ZIP archive. 
  • The lure led to an encoded PowerShell command, decoded and launched using a legitimate system utility, which retrieved and silently installed a rogue ScreenConnect remote access client. 
  • Further analysis identified that this threat actor very likely used a batch of echo commands to write out a file formatted to look like a PEM-formatted X.509 certificate, likely in an attempt to blend in with legitimate activity.  

What the Blackpoint SOC did 

  • The Blackpoint SOC isolated the affected host immediately upon identifying the malicious activity and notified the impacted customer. 

Why this matters 

  • The payload was disguised as a certificate file and decoded using a trusted Windows utility, a technique that can slip past controls looking for more obvious encoded-script patterns. 
  • Rapid isolation cut off the attacker’s remote access before it could be used for further compromise or lateral movement. 

BROC Weekly Snapshot 

What changed. What didn’t. What matters. 

Campaign Statuses 

Rogue RMM    Escalating   25% 
Fake CAPTCHA/ClickFix   Ongoing   19% 
SSL VPN Compromise   Ongoing   7% 
Trojanized Installers   Ongoing   4% 

Quick Take 

The Blackpoint APG has been tracking an ongoing campaign related to the malware framework, Avalon. The Blackpoint SOC has responded to several incidents involving this framework over the last 60 days. The Blackpoint APG has previously reported on this framework, which is delivered through a multi-stage phishing chain. Additionally, the Avalon framework maintains a ransom capability, internally named CrownX.  

The most recent samples identified indicate that the threat actor is likely improving the tool but continues to rely on similar naming conventions within their infrastructure (previously “helloxcherry”; now “lemonxhello”). Avalon shows significant indicators of AI assisted development, highlighting the increasing reliance on AI to develop multi-function tools that previously required significant expertise.  

Social engineering and business-related lures remain an effective and relied upon initial access vector and is likely to continue to be used over the next 12 months. It is likely that threat actors will continue to use AI-assistance to quickly create invoices, statements, and other lure documents tailored to the specific target over the next 12 months. 

DATE PUBLISHEDAugust 26, 2026
AUTHORAndi Ursry

The 2AM Test

Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours

GET YOUR COPY