PULSE the living trend engine
▲ Peaking Technology

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Operation BlueDash is leveraging fake Microsoft Teams updates to deploy remote monitoring and management tools for unauthorized PC control.

4sources
5articles
3velocity
+0%since first seen
2h agofirst detected

Velocity

How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →

The brief

A sophisticated phishing campaign identified as Operation BlueDash is currently targeting corporate environments. According to reports from The Hacker News and cyberpress.org, the operation utilizes fake Microsoft Teams updates to trick users into installing malicious software. Once these fake updates are executed, the attackers deploy a combination of remote monitoring and management tools, specifically Level RMM and ScreenConnect. The objective of this deployment is to establish persistence and provide the attackers with two separate ways to maintain control over the victim's computer. Coverage from several specialized outlets emphasizes the variety of tools being used in the attack chain. Cyberpress.org and The Hacker News both identify Level RMM and ScreenConnect as primary payloads, while cyberpress.org specifically notes the deployment of Tactical RMM as well.

Simultaneously, GBHackers reports that attackers are abusing the Microsoft Teams platform to impersonate IT support personnel. This social engineering tactic is designed to steal corporate access by gaining the trust of employees who believe they are interacting with legitimate technical staff during the update process. This trend arrives amid a broader surge in communication-based threats. CyberSecurityNews reports that Microsoft has detected 7.6 billion email phishing threats. Furthermore, the same outlet highlights a significant shift in attacker behavior, noting that vishing attacks targeting Microsoft Teams have increased ten-fold. This context suggests that Operation BlueDash is part of a wider strategic move by threat actors to migrate from traditional email-based phishing toward more interactive and trusted platforms like Teams to bypass security perceptions.

Future developments will likely center on the continued evolution of the Operation BlueDash toolset. Coverage indicates that the use of multiple RMM tools like Level RMM, ScreenConnect, and Tactical RMM allows for redundant control mechanisms. Observers should monitor for further reports on the specific corporate access points being targeted by the impersonation tactics detailed by GBHackers. The scale of the threat is underscored by the volume of phishing activity reported by Microsoft, suggesting that organizations should remain vigilant against deceptive IT support communications.

Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 1h ago.

Quick answers

What tools are used in Operation BlueDash?

The campaign deploys Level RMM, ScreenConnect, and Tactical RMM.

How are the attackers gaining access to PCs?

They use fake Microsoft Teams updates and impersonate IT support to steal corporate access.

What is the scale of phishing threats according to Microsoft?

Microsoft has detected 7.6 billion email phishing threats, with Teams vishing attacks increasing ten-fold.

Coverage (5)

Topics

Related trends

◼ Archived Technology 🔮 fades

New phishing kits target Microsoft 365 accounts, evade MFA

New phishing kits including Kratos and Forg365 are targeting Microsoft 365 accounts by evading multi-factor authentication through advanced technical maneuvers.

9 sources 13 articles v 10 12d ago
◼ Archived Business 🔮 fades

FBI warns Microsoft users about passwordless scam

The FBI has issued an alert regarding a new passwordless scam targeting Microsoft users amid a reported surge in AI-powered phishing.

5 sources 5 articles v 3 29d ago