news.mlab.sh
Back to the feed
threat-intel

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

High
Summary

A sophisticated phishing campaign, dubbed Operation BlueDash, is leveraging Microsoft Teams-themed lures to deliver malicious Remote Management and Monitoring (RMM) tools, primarily Level RMM and ConnectWise ScreenConnect. Threat actors, believed to be operating from Nigeria, are deploying a multi-brand scheme to establish persistent remote access, utilizing a series of phishing emails and a GitHub repository to host the malicious payloads. This campaign follows a pattern seen in previous attacks, including the JIVS PhishKit campaign, and is part of a broader trend of using RMM tools for malicious purposes.

A sophisticated phishing campaign, dubbed Operation BlueDash, is leveraging Microsoft Teams-themed lures to deliver malicious Remote Management and Monitoring (RMM) tools, primarily Level RMM and ConnectWise ScreenConnect. Threat actors, believed to be operating from Nigeria, are deploying a multi-brand scheme to establish persistent remote access, utilizing a series of phishing emails and a GitHub repository to host the malicious payloads. The campaign begins with emails mimicking a Teams update, directing victims to a fake Microsoft Store page at "teamvem[.]com" that downloads a malicious loader, "supportdev.exe." This loader then delivers Level RMM and ConnectWise ScreenConnect, alongside attempts to deploy ScreenConnect in parallel.

ZeroBEC has documented similar campaigns since at least February 2026, including the JIVS PhishKit campaign, which uses a provider-agnostic phishing page to steal corporate email credentials. The latest operation utilizes a GitHub repository ("Bluedashltd") to host the phishing source, CNAME configuration, and SupportDev payload. The commit history indicates activity since at least February 2026, when the repository was created.

Threat actors are conducting reconnaissance on the compromised host, running commands to determine system state, measure firewall profiles, and identify local Administrators group members. They are also utilizing a second repository ("rustovni") to host a Zoom meeting lure and its payload-delivery components, aiming to install Tactical RMM. The campaign’s multi-brand approach involves altering the workplace application lure, payload host, and remote management platform to maintain operational effectiveness.

This campaign follows the takedown of the Kratos (formerly Sneaky 2FA) phishing-as-a-service (PhaaS) kit by German authorities in collaboration with the U.S. and Indonesia, in addition to the arrest of its alleged developer and technical administrator. The operation is estimated to have earned more than €300,000 ($342,000) since 2024. More than 1,800 criminal enterprises are believed to have used Kratos, resulting in around 15,000 phishing campaigns per month.

Read the full article at The Hacker News