AUTO-UPDATED

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Cybersecurity researchers have identified Operation BlueDash, a sophisticated phishing campaign using fake Microsoft Teams updates to deploy remote monitoring tools and establish persistent unauthorized access to corporate systems.

Key Points

  • Attackers use a counterfeit Microsoft Store page, "teamvem[.]com," to trick users into downloading a malicious "supportdev.exe" file.
  • The malware installs legitimate remote monitoring and management (RMM) tools, specifically Level RMM and ConnectWise ScreenConnect, to maintain persistent access.
  • Operation BlueDash is attributed to a Nigeria-based threat actor group active since February 2026, utilizing GitHub infrastructure to host phishing payloads.
  • Once inside a system, attackers execute commands to enumerate local administrators, check firewall status, and determine if the host requires a reboot.
  • The campaign also employs a secondary Zoom-themed lure to distribute Tactical RMM agents, demonstrating a multi-brand strategy for compromising enterprise environments.

Why it Matters

This campaign highlights the growing trend of threat actors weaponizing legitimate administrative software to bypass traditional security defenses. By using authorized RMM tools, attackers can maintain persistent, stealthy access that often evades detection by standard endpoint security solutions.
Internet Published by info@thehackernews.com (The Hacker News)
Read original