Operation BlueDash Phishing Campaign Deploys Level RMM, ScreenConnect and Tactical RMM
ID: e1f730f7-2e8c-51b4-8a32-7cf77cc52d7c
STIX ID: report--e1f730f7-2e8c-51b4-8a32-7cf77cc52d7c
Feed Name: Cyber Press
ZeroBEC investigators uncovered "Operation BlueDash," a live phishing campaign that lures victims with a fake Microsoft Teams "secure document" flow and a counterfeit Microsoft Store "Teams update" page; executing the distributed Inno Setup loader (supportdev.exe) or JScript installer results in hidden PowerShell or script-driven downloads that enroll endpoints into attacker-controlled RMM platforms (Level RMM, ScreenConnect, Tactical RMM). The report documents public GitHub-hosted phishing infrastructure and payloads, observed hands-on reconnaissance commands post-enrollment, attribution to a Nigeria-based developer group, and concrete detection and mitigation recommendations for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
