Blackpoint SOC Threat Pulse: Week of 9/21

The Plot Clickens 

Blackpoint Cyber attack chain illustrating a ClickFix-style attack, ZIP extraction, registry persistence, SOC isolation, and prevention of further compromise

What we’re seeing 

  • The Blackpoint SOC alerted to a ClickFix style attack that tricked a user into running a PowerShell command through the Windows Run dialog.
  • The command downloaded a ZIP archive from attacker-controlled infrastructure, extracted it, hid the resulting folder, and established persistence through a registry Run key.
  • Analysis of the payload uncovered a wordlist encoded loader that reconstructed Lorem Ipsum associated shellcode in memory. The shellcode used a public WebMasterSun profile as a dead drop resolver before communicating with attacker infrastructure through victim specific BMP tasking, including delivery of a payload disguised as legitimate AWS disaster recovery software.

What the Blackpoint SOC did 

  • The Blackpoint SOC isolated the affected host within minutes of the alert to contain the activity and verified no lateral movement.
  • Conducted additional analysis of the shellcode’s communication protocol, characterized its observed C2 capabilities, and linked the activity to broader Lorem Ipsum and ClickFix tradecraft.

Why this matters 

  • The malware’s use of public dead drop infrastructure and image-based command and control can make malicious traffic resemble ordinary web activity. Detecting this type of intrusion requires connecting behaviors across the full attack chain, from ClickFix execution and persistence through victim specific tasking and post compromise activity.

BROC Weekly Snapshot

What changed. What didn’t. What matters.

Incidents Observed <100↑
Pre-Payload Disruptions 90%
Pre-Ransom Interruptions 3%

Campaign Statuses

Rogue RMM Ongoing 34%
Fake CAPTCHA/ClickFix Ongoing 21%
SSL VPN Compromise Ongoing 3%
Trojanized Installers Ongoing 1%

Quick Take 

The Blackpoint APG tracks emerging adversary techniques to ensure our SOC and customers remain informed of evolving threats and the behaviors that matter most for detection and response. This includes the increased use of blockchain infrastructure for command and control (C2); demonstrated by our analysis of ChainScript, a Node.js RAT that uses a Polygon smart contract to retrieve its active C2 endpoint. Separately, APG tracks “DeviceManagerAgent”, a separate Python RAT that uses an Ethereum smart contract to resolve its C2 infrastructure before communicating through a custom DNS protocol.

This approach allows operators to rotate infrastructure without modifying deployed malware, reducing the effectiveness of static indicators. As threat actors continue to adapt legitimate centralized technologies for malicious purposes, understanding these behaviors is critical to identifying suspicious activity beyond individual IP addresses and domains.

In Case You Missed It

The Blackpoint APG sent a threat notice this week to bring awareness to a zero-day vulnerability impacting Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC).

Cisco | CVE-2026-76460 | CVSS 10 Critical | Authentication Bypass

  • Potential Actions: Successful exploitation may allow the attacker to obtain command execution with root privileges, and no vendor workaround exists other than restricting management-plane access.
  • An unauthenticated remote attacker can send a crafted request to an affected API endpoint to bypass authentication and gain unauthorized access to the device’s web-based management interface.

The vulnerability was added to the CISA KEV Catalog on September 16, 2026.

Social Content

Blogs/Content

  • September 18, 2026: ChainScript: Tracing a Node.js RAT Through the Blockchain – LinkedIn | Blog
  • September 16, 2026: The APEX Wire: Remote Access & Identity – Blog

Threat Notices

DATE PUBLISHEDSeptember 22, 2026
AUTHORBlackpoint Cyber

The 2AM Test

Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours

GET YOUR COPY