Blackpoint SOC Threat Pulse: Week of 9/28

KongTuke Takes the Node Route

What we’re seeing 

  • The Blackpoint SOC alerted to suspicious cmd.exe activity on a host, consistent with a ClickFix-style attack that tricked a user into executing an obfuscated command through the Windows Run dialog. 
  • The chain downloads a legitimate Node.js runtime, performed system and domain discovery, and executed a screenshot capture module.  
  • For persistence, a registry entry was added to automatically spawn node.exe to execute a malicious file. 

What the Blackpoint SOC did 

  • The Blackpoint SOC isolated the affected host immediately upon detecting the suspicious command execution. 
  • The Blackpoint APG conducted additional analysis and research and identified the campaign is very likely tied to ongoing KongTuke, a malicious traffic distribution system, activity that has been frequently reported to deliver multiple loaders, including MintsLoader, and second stage payloads, including NodeSnake RAT.  

Why this matters 

  • ClickFix-style social engineering bypasses file-based detections by having the user execute the malicious command themselves through a native Windows dialog; its widespread adoption is very likely driven by its effectiveness as a low-cost, socially engineered access technique. 
  • The KongTuke activity and deployment of NodeSnake has been tied to the Interlock Ransomware group, and often acts as a persistence mechanism and downloader for additional payloads. 

BROC Weekly Snapshot

What changed. What didn’t. What matters.

Incidents Observed >100↑
Pre-Payload Disruptions 90%
Pre-Ransom Interruptions 4%

Campaign Statuses

Rogue RMM ↑ Ongoing 35%
Fake CAPTCHA/ClickFix ↑ Ongoing 24%
SSL VPN Compromise ↑ Ongoing 4%
Trojanized Installers ↑ Ongoing 4%

What Blackpoint is Doing 

Blackpoint continuously monitors the threat landscape for emerging activity affecting customer environments, including ransomware operations, vulnerability exploitation, and other threats. The SOC provides 24/7 monitoring and response, while APG tracks changes in adversary behavior, campaigns, and vulnerabilities to provide intelligence that supports detection, investigation, and response. Together, these capabilities help identify and respond to malicious activity before it can escalate into broader operational or business impact. 

Blackpoint has detections in place for key behaviors across the infection chain and continues to create and improve detections as the ClickFix-style attacks continue to be adopted and evolve. 

Recommendations

  • Reduce the impact of ClickFix social engineering. Train users never to paste commands into PowerShell, Command Prompt, or the Windows Run dialog when prompted by a website, CAPTCHA, support page, or browser message. 
  • Restrict PowerShell and script execution. Use Group Policy, application control, and constrained administration policies to limit unapproved PowerShell and script execution, particularly for standard users. 
  • Deploy malvertising blockers and web filtering solutions. This isolates or blocks access to the compromised WordPress sites and rogue traffic distribution systems (TDS) that KongTuke rents. 

In Case You Missed It

The Blackpoint APG sent a threat notice this week to bring awareness to a zero-day vulnerability impacting F5 BIG-IP Access Policy Manager (APM). 

F5 | CVE-2026-94127 | CVSS 9.8 Critical | Heap-based Buffer Overflow 

  • Potential Actions: An unauthenticated attacker can send crafted traffic to a BIG-IP virtual server configured with both an APM access policy and an OAuth authorization server profile to trigger a heap-based buffer overflow and execute arbitrary code on the underlying system. 
  • The vulnerability affects only systems where APM is configured as an OAuth authorization server, and restricting access to the management interface does not prevent exploitation because the malicious traffic is sent directly to the virtual server. 

The vulnerabilty was added to the CISA KEV Catalog on September 22, 2026.  

Social Content

Blogs/Content

Threat Notices

DATE PUBLISHEDOctober 1, 2026
AUTHORAndi Ursry

The 2AM Test

Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours

GET YOUR COPY