Blackpoint SOC Threat Pulse: Week of 10/5
Featured Incident
Snow Place Like Teams
What we’re seeing
- The Blackpoint SOC alerted to suspicious browser extension activity, consistent with public reporting of the malicious SNOWBELT extension.
- Further analysis identified a suspicious executable retrieved to the user’s OneDrive Downloads folder that ran an AutoHotKey script to install the extension, then deleted both files.
- The host then performed reconnaissance to identify domain administrators and enumerate LDAP services, suggesting intent to escalate privileges.
- The initial access method likely stemmed from a Microsoft Teams-based IT support scam.
What the Blackpoint SOC did
- The Blackpoint SOC isolated the host immediately upon identifying the malicious extension activity.
- Conducted additional analysis into the execution chain and reconnaissance activity, confirming no further lateral movement or compromise of the user’s M365 account.
Why this matters
- The initial access vector is consistent with public reporting on similar campaigns; this activity and ties to the SNOWBELT browser-extension backdoor to UNC6692, a group known for mass email-bombing with fake Microsoft Teams IT support scams to deliver the “Snow” malware family.
- Teams-based helpdesk impersonation is a growing initial access vector likely due to it being a trusted internal collaboration tool. Where phishing emails face greater scrutiny, trusted tools like Microsoft Teams often do not, making them an effective attack vector.
What Blackpoint is Doing
Blackpoint has detections in place for key behaviors across the infection chain and activity related to SNOWBELT activity. The SOC provides 24/7 monitoring and response, while APG tracks changes in adversary behavior, campaigns, and vulnerabilities to provide intelligence that supports detection, investigation, and response. Together, these capabilities help identify and respond to malicious activity before it can escalate into broader operational or business impact.
Recommendations
- Restrict who can message users on Microsoft Teams. Block or require approval for chats from external/unverified tenants as this is the delivery method for fake IT support scams.
- Train employees to recognize that legitimate IT support will not cold-contact them over Teams. This includes asking them to run a script, install a “patch”, or join a screen-share to fix a spam problem.
- Enforce application and browser-extension allowlisting. This can help ensure that unauthorized or sideloaded Chromium extensions cannot install or run.
- Disable or tightly restrict AutoHotKey and similar scripting-engine execution. Ensuring users that do not have a business need are disabled can limit the success a campaign has.
- Strengthen email filtering and anti-spam controls. Email bombing is a frequently observed technique in this campaign and anti-spam controls can help interrupt this activity before an attack is successful.
BROC Weekly Snapshot
What changed. What didn’t. What matters.
Campaign Statuses
In Case You Missed It
The Blackpoint APG sent a threat notice this week to bring awareness to a zero-day vulnerability impacting F5 BIG-IP Access Policy Manager (APM).
Citrix | CVE-2026-88771 | CVSS 9.5 Critical | Improper Input Validation
- Potential Actions: An unauthenticated attacker can exploit this vulnerability to run arbitrary commands on the appliance.
Citrix | CVE-2026-88772 | CVSS 9.5 Critical | Memory Overflow
- Potential Actions: An attacker can exploit this vulnerability to achieve remote code execution or cause a denial-of-service condition.
- This vulnerability affects appliances with DTLS enabled, which is on by default for VPN virtual servers on NetScaler Gateway.
These vulnerabilities were added to the CISA KEV Catalog on September 28, 2026.
Social Content
Threat Notices
- October 2, 2026: Fortinet FortiMail Vulnerability – LinkedIn | infosec.exchange
- September 30, 2026: Cisco Catalyst SD-WAN Vulnerability – LinkedIn | infosec.exchange
- September 29, 2026: WatchGuard AP Vulnerabilities – LinkedIn | infosec.exchange
- September 28, 2026: Citrix NetScaler ADC and Gateway Vulnerabilities – LinkedIn | infosec.exchange
DATE PUBLISHEDOctober 7, 2026
AUTHORBlackpoint Cyber
SHARE ON
The 2AM Test
Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours