Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
ID: 7b3e849e-4136-557b-9c06-ea1c64986e61
STIX ID: report--7b3e849e-4136-557b-9c06-ea1c64986e61
Feed Name: The Hacker News
ZeroBEC has documented "Operation BlueDash," a Microsoft Teams- and Zoom-themed phishing campaign that coerces victims into downloading a loader (supportdev.exe) which runs hidden PowerShell to fetch legitimate RMM tools (Level RMM, ConnectWise ScreenConnect, Tactical RMM) and register the host using attacker-controlled enrollment tokens; the campaign uses GitHub Pages and custom domains for phishing infrastructure and has been attributed with moderate-to-high confidence to operators in Nigeria. The report also highlights credential-harvesting activity (JIVS PhishKit) and references the broader abuse of RMMs and recent takedowns of phishing kits like Kratos.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
