Blackpoint SOC Threat Pulse: Week of September 7, 2026
In this week’s Threat Pulse, the Blackpoint Security Operations Center (SOC) unpacks an attack that hid a remote access trojan inside a trojanized cryptocurrency wallet application, deployed through a double-extension file disguised as an insurance document, with the payload injected directly into memory to avoid ever touching disk. Plus, the Blackpoint Adversary Pursuit Group (APG) reports a sharp rise in trojanized installer campaigns over the past 90 days, and two critical SonicWall SMA1000 vulnerabilities, already tied to real-world exploitation, land on this week’s watch list.
Featured Incident
No Exodus for this RAT
What we’re seeing
- The Blackpoint SOC alerted to suspicious JavaScript execution after a user ran a file disguised with a double PDF/script extension; the document appeared to be a legitimate insurance-related document.
- The script opened a decoy document while silently downloading and installing a trojanized cryptocurrency wallet application via a silent MSI install.
- Additional analysis identified the bundle was a .js loader that was designed to decrypt and inject a modular remote access trojan, RMMProject, capable of browser credential theft, VNC access, and network proxying, tasked through cloud storage infrastructure.
What the Blackpoint SOC did
- The Blackpoint SOC isolated the affected host immediately upon detecting the suspicious script execution.
- The Blackpoint SOC identified the payload and traced the attack chain from the initial lure through the trojanized installer.
Why this matters
- Hiding malicious code inside a real wallet application allows payloads to run without ever touching disk as a separate executable; a pattern that can slip past traditional file-based detections.
- The Blackpoint’s SOC isolated the device before the loader could reach out for tasking, underscoring the value of expert led behavioral analysis and quick response.
BROC Weekly Snapshot
What changed. What didn’t. What matters.
Campaign Statuses
| Rogue RMM | ↑ | Escalating | 31% |
| Fake CAPTCHA/ClickFix | ↓ | Ongoing | 19% |
| SSL VPN Compromise | ↓ | Ongoing | 4% |
| Trojanized Installers | ↑ | Ongoing | 4% |
Quick Take
Over the previous 90 days, the Blackpoint APG has been tracking an increase in trojanized installers used to deploy malicious payloads. The Blackpoint SOC has observed more than 50 incidents related to trojanized installers between 01 June and 03 September 2026. The Blackpoint SOC interrupted more than 95% of these incidents before any second-stage payloads could be deployed.
Of the total incidents observed, roughly 70% are related to the deployment of rogue RMM tools, with the highest observed being ScreenConnect. Trojanized installer incidents increased 85% from July to August 2026, with the deployment of rogue ScreenConnect instances.
The trojanized installers observed by the Blackpoint SOC include meeting platforms (Microsoft Teams, Zoom, Google Meet), Adobe tools, AI platforms, and more. As threat actors shift away from traditional, detectable attack vectors and turn to “legitimate” tools that are less likely to be detected by traditional security tooling, it is likely that the use of trojanized installers will increase.
Additionally, as interest in AI tools increases, threat actors are likely to continue to utilize lures related to AI platforms and tooling to gain initial access and remain undetected.
DATE PUBLISHEDSeptember 9, 2026
AUTHORBlackpoint Cyber
SHARE ON
The 2AM Test
Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours