Blackpoint SOC Threat Pulse: Week of August 31, 2026
In this week’s Threat Pulse, the Blackpoint Security Operations Center (SOC) stopped a phishing attack that used an executable disguised as a PDF document and DLL sideloading through a legitimate PDF reader to deploy DonutLoader and Remcos RAT. Additionally, the Blackpoint Adversary Pursuit Group (APG) examines the continued abuse of legitimate remote monitoring and management (RMM) software, which accounted for 22% of incidents over the previous 30 days. The Blackpoint APG also released a threat notice related to an actively exploited remote code execution vulnerability affecting Zimbra Collaboration Suite.
Featured Incident
PDFinitely Not What It Seemed
What we’re seeing
- The Blackpoint SOC alerted to suspicious process activity on a host; further investigation revealed the user clicked a phishing link that led to a spoofed vendor onboarding page.
- The page prompted download of an archive file and sandbox analysis identified the archive contained an executable disguised as a PDF document, which used DLL sideloading to run malicious code through a legitimate PDF reader application.
- Analyst by the Blackpoint APG team identified the final payloads as DonutLoader and Remcos RAT, each designed to provide persistence, deploy second stage payloads, and allow data exfiltration.
What the Blackpoint SOC did
- The Blackpoint SOC isolated the affected host immediately upon detecting the suspicious activity, effectively cutting off threat actor access to the host and preventing additional malicious activity.
Why this matters
- DLL sideloading lets malicious code run through a trusted, legitimately signed application, making it harder to flag with traditional detection.
- Rapid isolation prevented the activity from spreading beyond the initial host, with no lateral movement observed.
BROC Weekly Snapshot
What changed. What didn’t. What matters.
Campaign Statuses
| Fake CAPTCHA/ClickFix | ↑ | Escalating | 31% |
| Rogue RMM | ↓ | Ongoing | 23% |
| SSL VPN Compromise | — | Ongoing | 5% |
| Trojanized Installers | — | Ongoing | 3% |
| Fake Update | — | Ongoing | 2% |
Quick Take
The Blackpoint APG team tracks the abuse of legitimate software; the second highest campaign in 2026 is the deployment of rogue RMM tools. Over the previous 30 days, the Blackpoint SOC has responded to more than 120 incidents related to the deployment of rogue RMM tools, accounting for 22% of incidents. Nearly 13% of these incidents began with a trojanized installer meant to look like legitimate tools, like Adobe, Claude, and Microsoft Teams.
The most frequently observed rogue RMM deployed over the last 30 days is ScreenConnect, observed in 84%; a large portion of these incidents involve the deployment of more than one RMM tool. The use of multiple RMM tools is likely an attempt to maintain persistence in the event one of the tools is detected. These tools blend in with expected IT activity and are likely going to continue to be deployed over the next 12 months; this is where Blackpoint’s Managed Application Control (MAC) product suite shines. MAC helps to quickly alert and block malicious activity masquerading as legitimate remote software.
DATE PUBLISHEDAugust 31, 2026
AUTHORBlackpoint Cyber
SHARE ON
The 2AM Test
Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours