256 Newsroom — Uganda's Digital News Infrastructure
Consumer Technology

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update - The Hacker News

Share
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update - The Hacker News
Image · Internet

What the report says

The Hacker News reported that cybersecurity firm ZeroBEC has identified a Microsoft Teams-themed phishing campaign, tracked as Operation BlueDash, that uses “secure document” messages to trick victims into installing legitimate remote monitoring and management tools. According to the report, targets are sent through compromised web infrastructure to a fake Microsoft Store page, including the domain teamvem[.]com, where they are told Teams must be updated before a shared file can be opened.

The downloaded file, described as supportdev.exe, is an Inno Setup-based loader that runs PowerShell in the background, retrieves the official Level RMM installer and enrolls the device using an attacker-controlled secret. ZeroBEC also found the same command deploying ConnectWise ScreenConnect, while related infrastructure and repositories indicate a Zoom-themed variant that installs Tactical RMM. Researchers assessed that using several RMM tools may give attackers backup access if one tool is detected or removed.

ZeroBEC attributed Operation BlueDash with moderate-to-high confidence to a threat actor operating from Nigeria, citing infrastructure, code history and a GitHub environment connected to the activity. The company said repository evidence suggests the campaign has been active since at least February 2026. After gaining access, operators reportedly ran reconnaissance commands to check reboot status, firewall profiles, disk protection and local administrator membership.

The report places BlueDash within a broader pattern of attackers abusing trusted remote management software through workplace-themed lures. Such tools are commonly used by IT teams, which can make malicious use harder to distinguish unless organizations monitor for unauthorized RMM enrollment, unusual PowerShell activity and remote access sessions outside approved support workflows.

Read the full report at Internet →

Loading debate for this article…

Other publishers covering this story

No additional verified coverage is currently clustered with this report.

Related reporting