logo

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

ID: 7b3e849e-4136-557b-9c06-ea1c64986e61

STIX ID: report--7b3e849e-4136-557b-9c06-ea1c64986e61

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-07-27

Date Updated: 2026-07-27

Author: [email protected] (The Hacker News)

...
...

ZeroBEC has documented "Operation BlueDash," a Microsoft Teams- and Zoom-themed phishing campaign that coerces victims into downloading a loader (supportdev.exe) which runs hidden PowerShell to fetch legitimate RMM tools (Level RMM, ConnectWise ScreenConnect, Tactical RMM) and register the host using attacker-controlled enrollment tokens; the campaign uses GitHub Pages and custom domains for phishing infrastructure and has been attributed with moderate-to-high confidence to operators in Nigeria. The report also highlights credential-harvesting activity (JIVS PhishKit) and references the broader abuse of RMMs and recent takedowns of phishing kits like Kratos.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.