Cybersecurity researchers have identified Operation BlueDash, a sophisticated phishing campaign using fake Microsoft Teams updates to deploy remote monitoring tools and establish persistent unauthorized access to corporate systems.
Key Points
- Attackers use a counterfeit Microsoft Store page, "teamvem[.]com," to trick users into downloading a malicious "supportdev.exe" file.
- The malware installs legitimate remote monitoring and management (RMM) tools, specifically Level RMM and ConnectWise ScreenConnect, to maintain persistent access.
- Operation BlueDash is attributed to a Nigeria-based threat actor group active since February 2026, utilizing GitHub infrastructure to host phishing payloads.
- Once inside a system, attackers execute commands to enumerate local administrators, check firewall status, and determine if the host requires a reboot.
- The campaign also employs a secondary Zoom-themed lure to distribute Tactical RMM agents, demonstrating a multi-brand strategy for compromising enterprise environments.