Blackpoint SOC Threat Pulse: Week of 9/14
In this week’s Threat Pulse, the Blackpoint SOC breaks down an attack chain that combined a rogue Quick Assist instance with ClickFix-style social engineering, tricking a user into running a command through the Windows Run dialog that installed a backup application from attacker-controlled infrastructure. Additionally, the Blackpoint APG‘s 90-day review shows ClickFix-style attacks now account for nearly a third of all confirmed incidents. The Blackpoint APG released a threat notice related to two critical, unauthenticated vulnerabilities in Check Point’s VPN certificate handling.
Featured Incident
Backup Denied
What we’re seeing
- The Blackpoint SOC observed a user running rogue Quick Assist instance and reconnaissance commands on a host.
- The Blackpoint SOC then alerted to ClickFix-style command techniques launched through the Windows Run Dialog.
- A PowerShell command was run to download and install a backup application from attacker-controlled infrastructure.
What the Blackpoint SOC did
- The Blackpoint SOC immediately isolated the device upon identifying the malicious activity to prevent further action and cut off attacker access to the host.
- Conducted additional investigation to identify persistence, such as the rogue remote access tool, and verified no lateral movement.
Why this matters
- This incident demonstrates how legitimate tools, like Quick Assist and ClickFix-style techniques can turn a simple user interaction into remote access and persistence on a host.
- Rapid SOC detection and isolation prevented the attacker from progressing their access and maintaining persistence.
BROC Weekly Snapshot
What changed. What didn’t. What matters.
Campaign Statuses
| Rogue RMM | ↑ | Ongoing | 32% |
| Fake CAPTCHA/ClickFix | ↑ | Ongoing | 24% |
| SSL VPN Compromise | − | Ongoing | 4% |
| Trojanized Installers | ↓ | Ongoing | 1% |
| Fake Updates | ↑ | Ongoing | 1% |
Quick Take
Over the previous 12 months, the Blackpoint APG has been tracking the increasing use of ClickFix-style attacks for initial access. Over the previous 90 days, the Blackpoint SOC has responded to more than 470 confirmed ClickFix-style attacks, accounting for 32% of total incidents in that time. More than 85% of these incidents have been interrupted before an initial payload could be executed and even more were stopped before the attacker could complete their objectives.
The overarching ClickFix campaigns include multiple sub-campaigns, which include a campaign deploying multiple versions of CastleLoader, the deployment of NodeSnake tied to the Interlock Ransomware operation, and the deployment of a remote access trojan where the command and control uses an Ethereum smart contract to resolve its active infrastructure. This campaign continues to be the most frequently observed campaign in 2026.
The technique has been widely adopted by malware-as-a-service (MaaS) and ransomware-as-a-service (RaaS) operations, other financially motivated cybercriminals, and nation-state threat actors. Its widespread adoption is very likely driven by its effectiveness as a low-cost, socially engineered access technique. As ClickFix becomes increasingly common across the threat landscape, it also becomes more difficult to attribute activity based on the initial access method alone, reinforcing the need for intelligence-driven defensive measures.
DATE PUBLISHEDSeptember 15, 2026
AUTHORBlackpoint Cyber
SHARE ON
The 2AM Test
Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours