logo

A Fake Teams Update Can Give Hackers Two Separate Ways to Control Your PC

ID: 9e0e456c-2421-5b6a-8099-49012bc73151

STIX ID: report--9e0e456c-2421-5b6a-8099-49012bc73151

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-07-27

Date Updated: 2026-07-28

Author: Guru Baran

...
...

Operation BlueDash is a phishing campaign that lures recipients with a fake Microsoft Teams update; when executed the payload runs an Inno Setup installer that launches a hidden PowerShell to silently install legitimate remote-monitoring/remote-access tools (Level RMM and ScreenConnect) using hardcoded credentials, creating redundant remote access and enabling operators to perform manual reconnaissance. Researchers observed infrastructure rotation, linked campaigns (Zoom-themed and SEO-poisoned installers), and recommend defenses such as verifying updates via official channels, allowlisting approved RMM tools, detecting hidden PowerShell from installers, enforcing MFA, and monitoring local administrator changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.