Blackpoint SOC Threat Pulse: Week of 9/21
Featured Incident
The Plot Clickens
What we’re seeing
- The Blackpoint SOC alerted to a ClickFix style attack that tricked a user into running a PowerShell command through the Windows Run dialog.
- The command downloaded a ZIP archive from attacker-controlled infrastructure, extracted it, hid the resulting folder, and established persistence through a registry Run key.
- Analysis of the payload uncovered a wordlist encoded loader that reconstructed Lorem Ipsum associated shellcode in memory. The shellcode used a public WebMasterSun profile as a dead drop resolver before communicating with attacker infrastructure through victim specific BMP tasking, including delivery of a payload disguised as legitimate AWS disaster recovery software.
What the Blackpoint SOC did
- The Blackpoint SOC isolated the affected host within minutes of the alert to contain the activity and verified no lateral movement.
- Conducted additional analysis of the shellcode’s communication protocol, characterized its observed C2 capabilities, and linked the activity to broader Lorem Ipsum and ClickFix tradecraft.
Why this matters
- The malware’s use of public dead drop infrastructure and image-based command and control can make malicious traffic resemble ordinary web activity. Detecting this type of intrusion requires connecting behaviors across the full attack chain, from ClickFix execution and persistence through victim specific tasking and post compromise activity.
BROC Weekly Snapshot
What changed. What didn’t. What matters.
Campaign Statuses
| Rogue RMM | ↑ | Ongoing | 34% |
| Fake CAPTCHA/ClickFix | ↓ | Ongoing | 21% |
| SSL VPN Compromise | ↓ | Ongoing | 3% |
| Trojanized Installers | − | Ongoing | 1% |
Quick Take
The Blackpoint APG tracks emerging adversary techniques to ensure our SOC and customers remain informed of evolving threats and the behaviors that matter most for detection and response. This includes the increased use of blockchain infrastructure for command and control (C2); demonstrated by our analysis of ChainScript, a Node.js RAT that uses a Polygon smart contract to retrieve its active C2 endpoint. Separately, APG tracks “DeviceManagerAgent”, a separate Python RAT that uses an Ethereum smart contract to resolve its C2 infrastructure before communicating through a custom DNS protocol.
This approach allows operators to rotate infrastructure without modifying deployed malware, reducing the effectiveness of static indicators. As threat actors continue to adapt legitimate centralized technologies for malicious purposes, understanding these behaviors is critical to identifying suspicious activity beyond individual IP addresses and domains.
In Case You Missed It
The Blackpoint APG sent a threat notice this week to bring awareness to a zero-day vulnerability impacting Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC).
Cisco | CVE-2026-76460 | CVSS 10 Critical | Authentication Bypass
- Potential Actions: Successful exploitation may allow the attacker to obtain command execution with root privileges, and no vendor workaround exists other than restricting management-plane access.
- An unauthenticated remote attacker can send a crafted request to an affected API endpoint to bypass authentication and gain unauthorized access to the device’s web-based management interface.
The vulnerability was added to the CISA KEV Catalog on September 16, 2026.
Social Content
Blogs/Content
- September 18, 2026: ChainScript: Tracing a Node.js RAT Through the Blockchain – LinkedIn | Blog
- September 16, 2026: The APEX Wire: Remote Access & Identity – Blog
Threat Notices
- September 17, 2026: Cisco ISE/ISE-PIC – LinkedIn | infosec.exchange
- September 16, 2026: Check Point Security Management – LinkedIn | infosec.exchange
- September 15, 2026: Cisco Secure Email Gateway – infosec.exchange
DATE PUBLISHEDSeptember 22, 2026
AUTHORBlackpoint Cyber
SHARE ON
The 2AM Test
Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours