Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
Operation BlueDash is leveraging fake Microsoft Teams updates to deploy remote monitoring and management tools for unauthorized PC control.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
A sophisticated phishing campaign identified as Operation BlueDash is currently targeting corporate environments. According to reports from The Hacker News and cyberpress.org, the operation utilizes fake Microsoft Teams updates to trick users into installing malicious software. Once these fake updates are executed, the attackers deploy a combination of remote monitoring and management tools, specifically Level RMM and ScreenConnect. The objective of this deployment is to establish persistence and provide the attackers with two separate ways to maintain control over the victim's computer. Coverage from several specialized outlets emphasizes the variety of tools being used in the attack chain. Cyberpress.org and The Hacker News both identify Level RMM and ScreenConnect as primary payloads, while cyberpress.org specifically notes the deployment of Tactical RMM as well.
Simultaneously, GBHackers reports that attackers are abusing the Microsoft Teams platform to impersonate IT support personnel. This social engineering tactic is designed to steal corporate access by gaining the trust of employees who believe they are interacting with legitimate technical staff during the update process. This trend arrives amid a broader surge in communication-based threats. CyberSecurityNews reports that Microsoft has detected 7.6 billion email phishing threats. Furthermore, the same outlet highlights a significant shift in attacker behavior, noting that vishing attacks targeting Microsoft Teams have increased ten-fold. This context suggests that Operation BlueDash is part of a wider strategic move by threat actors to migrate from traditional email-based phishing toward more interactive and trusted platforms like Teams to bypass security perceptions.
Future developments will likely center on the continued evolution of the Operation BlueDash toolset. Coverage indicates that the use of multiple RMM tools like Level RMM, ScreenConnect, and Tactical RMM allows for redundant control mechanisms. Observers should monitor for further reports on the specific corporate access points being targeted by the impersonation tactics detailed by GBHackers. The scale of the threat is underscored by the volume of phishing activity reported by Microsoft, suggesting that organizations should remain vigilant against deceptive IT support communications.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 1h ago.
Quick answers
What tools are used in Operation BlueDash?
The campaign deploys Level RMM, ScreenConnect, and Tactical RMM.
How are the attackers gaining access to PCs?
They use fake Microsoft Teams updates and impersonate IT support to steal corporate access.
What is the scale of phishing threats according to Microsoft?
Microsoft has detected 7.6 billion email phishing threats, with Teams vishing attacks increasing ten-fold.
Coverage (5)
- Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold CyberSecurityNews · 1d ago
- Operation BlueDash Phishing Campaign Deploys Level RMM, ScreenConnect and Tactical RMM cyberpress.org · 1d ago
- Attackers Abuse Microsoft Teams to Impersonate IT Support and Steal Corporate Access gbhackers.com · 1d ago
- A Fake Teams Update Can Give Hackers Two Separate Ways to Control Your PC CyberSecurityNews · 1d ago
- Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update The Hacker News · 1d ago
Topics
Related trends
Microsoft stops rollout of some Teams and Outlook features
Microsoft is halting the rollout of specific Teams and Outlook features while pivoting certain capabilities behind a Copilot subscription paywall.
Can't log in? Microsoft outage hits Teams, Outlook and more
A series of connectivity failures across Microsoft Azure and various consumer services disrupted operations globally on July 23, 2026.
New phishing kits target Microsoft 365 accounts, evade MFA
New phishing kits including Kratos and Forg365 are targeting Microsoft 365 accounts by evading multi-factor authentication through advanced technical maneuvers.
FBI warns Microsoft users about passwordless scam
The FBI has issued an alert regarding a new passwordless scam targeting Microsoft users amid a reported surge in AI-powered phishing.
‘Build Vice City’: the GTA 6 scam that’s hitting gamers worldwide
A surge in fraudulent GTA 6 beta invites and pre-order sites is targeting gamers worldwide to harvest sensitive personal and financial data.
FBI issues urgent Kali365 security warning for Teams, Outlook, OneDrive users
11 news sources are covering this Technology story right now — PULSE is tracking how fast it spreads.