Cybersecurity researchers have uncovered a new phishing campaign called Operation BlueDash that tricks users into installing legitimate remote management tools through a fake Microsoft Teams update. The attackers send phishing emails containing a so-called secure document that appears genuine. When victims try to open the file, they are redirected to a fake Microsoft Store page. The page falsely claims that Microsoft Teams must be updated before the document can be viewed.

microsoft-teams-logo-operation-bluedash-fake-update-attack

Instead of downloading a real Teams update, victims receive a malicious installer known as supportdev.exe. This installer silently launches a hidden PowerShell process in the background without the user’s knowledge. The script then downloads the official Level RMM software and automatically registers the infected device using an attacker-controlled enrollment key. Because the software itself is legitimate, the attack can easily avoid suspicion during the early stages.

Researchers also found that the same PowerShell command installs ConnectWise ScreenConnect alongside Level RMM. By deploying more than one remote management tool, the attackers increase their chances of keeping access to the compromised system. If one tool is detected and removed by security software, the second tool can continue providing remote access. This technique helps the attackers maintain long-term control over infected devices.

phishing-email-remote-access-tool-cyberattack-operation-bluedash

According to researchers, this is not the first time cybercriminals have abused trusted remote management software. Earlier phishing campaigns used fake workplace meeting invitations and PDF attachments to install tools such as ScreenConnect, Tactical RMM, and MeshAgent. These applications are commonly used by IT administrators, making them less likely to raise immediate security concerns. Operation BlueDash follows the same strategy by misusing trusted software for malicious purposes.

The campaign has been linked with moderate-to-high confidence to a threat group believed to be operating from Nigeria. Researchers reached this conclusion after examining the attackers’ infrastructure, code history, and GitHub resources connected to the campaign. Evidence suggests that the operation has been active since at least February 2026, when the fake Microsoft Teams update page first appeared in the attackers’ repository.

fake-zoom-update-tactical-rmm-operation-bluedash-attack

After gaining access, the attackers begin collecting information about the compromised computer. They run commands to check whether the system is waiting for a reboot, whether the drive is protected by encryption, which firewall profiles are active, and who belongs to the local Administrators group. This information helps them understand the security environment before deciding their next actions inside the victim’s network.

Researchers also discovered another GitHub repository connected to the same threat actor that uses a fake Zoom meeting update instead of Microsoft Teams. In this version of the attack, victims are tricked into downloading Tactical RMM from its official GitHub release. The software is then installed and registered using an embedded authentication token controlled by the attackers. This shows the group is using multiple trusted brands while keeping the same attack method.

endpoint-security-dashboard-remote-access-threat-detection

Security experts say Operation BlueDash demonstrates how attackers continue to misuse legitimate remote management tools to gain persistent access to victim systems. Because these applications are widely trusted in business environments, they can blend into normal IT activity and become harder to detect. Organizations should remain cautious when receiving unexpected document-sharing emails, verify software updates only through official sources, and closely monitor unauthorized use of remote management tools across their networks.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news