Close Menu
    What's Hot

    Lawyers, teachers, and students face consequences when they use AI to do their jobs. What about politicians?

    Trump Backs New Talks but It’s Unclear What He Hopes to Achieve This Time

    Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

    Facebook X (Twitter) Instagram
    Trending
    • Lawyers, teachers, and students face consequences when they use AI to do their jobs. What about politicians?
    • Trump Backs New Talks but It’s Unclear What He Hopes to Achieve This Time
    • Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
    • Opinion | A Setback for the MAGA Media Takeover
    • France Records Its First-Ever Pyrocumulonimbus Cloud Amid Record-Smashing Fires
    • Cadence Design Systems, Inc. (CDNS) Q2 2026 Earnings Call Transcript
    • PGA Tour: Lucas Glover clears up AimPoint speculation after removing shoes during round | Golf News
    • Quiz: Find the Right Style of Sunglasses for Your Personality
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

    adminBy adminJuly 28, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

    Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs “secure document” lures to deliver legitimate remote monitoring and management (RMM) tools.

    “The victim was directed through compromised web infrastructure to a counterfeit Microsoft Store page claiming that Microsoft Teams had to be updated before the shared document could be opened,” ZeroBEC said in a report published last week. The bogus Teams page in question is “teamvem[.]com.”

    The active download is used to deliver “supportdev.exe,” an Inno Setup-based loader that launches PowerShell in a hidden window, fetches an official Level RMM installer, and registers the endpoint using an attacker-controlled enrollment secret (“LEVEL_API_KEY=GxSCHE8EZwfyYN3iPQHPai8D”).

    The same PowerShell command has been found to download and deploy ConnectWise ScreenConnect in parallel, indicating an attempt to drop multiple RMM tools with an intent to establish persistent remote access.

    This is not the first time threat actors have abused RMM tools to their advantage. Earlier this year, Microsoft warned of multiple phishing campaigns that used workplace meeting lures and PDF attachments to distribute signed malware dubbed TrustConnect, which then acted as a conduit for ScreenConnect, along with other RMM programs like Tactical RMM and MeshAgent.

    Cybersecurity

    Another campaign documented by ZeroBEC in May 2026 involved the use of phishing emails that purported to share secure documents in order to kick off an attack chain that stealthily dropped RMM backdoors.

    The latest set of phishing attacks has been codenamed Operation BlueDash, with the email security company attributing it with moderate-to-high confidence to a threat actor group operating from Nigeria based on an analysis of infrastructure, code history, and a GitHub environment used to operate the campaigns.

    The deployment of multiple RMM tools on the same host is seen as an attempt to set up redundant access and improve resilience in the event one of the programs is detected and removed from the environment.

    Subsequently, the threat actors have been observed attempting to explore the infected host, running commands to determine if it’s pending a reboot or whether the system volume was protected, measure active firewall profiles, enumerate members of the local Administrators group, and identify the local Administrators group name.

    “This sequence suggests a practical operator checklist: determine system state, understand encryption and firewall posture, and identify privileged local users before deciding how to continue,” ZeroBEC said. “It also provides defenders with a behavioral detection opportunity because the commands originate through an unauthorized RMM context rather than an approved IT workflow.”

    Further analysis of the threat actor infrastructure (“support[.]berrydev[.]xyz”) has uncovered a GitHub Pages domain (“berry4603.github[.]io”) and a repository named “Bluedashltd” that contains the phishing source, CNAME configuration, and SupportDev payload. The commit history indicates that the campaign has been active since at least February 2026, when the repository was created with the fake Microsoft Store page featuring an “update” for Teams.

    What’s more, a second repository (“rustovni”) tied to the same GitHub account has been found to host a Zoom meeting lure along with its payload-delivery components. The end goal, in this case, is to download the Tactical RMM agent from its official GitHub release, install it in the Windows temporary directory, and register the compromised host with the attacker using an embedded authentication token.

    Cybersecurity

    The Zoom-themed operation also suggests that the threat actors are running a multi-brand scheme that keeps the core intact, while altering the workplace application lure, payload host, and the remote management platform.

    The disclosure comes as ZeroBEC detailed JIVS PhishKit, a coordinated mailbox credential-harvesting campaign targeting multiple users within the same organization to deliver a provider-agnostic phishing page that can target Microsoft 365, Google Workspace, cPanel, Roundcube, Zimbra, and other email identities. The earliest artifact related to the effort dates back to August 21, 2025.

    “The messages used an authenticated but unrelated external sender, warned that each recipient mailbox had violated policy, and directed users to a live PHP phishing page on corychase[.]org,” the company said. “The landing page was not a Microsoft clone. It presented a generic ‘Session Expired’ form that could be used against Microsoft 365, Google Workspace, hosted webmail, or almost any corporate identity.”

    The kit is designed to siphon a corporate email address and the password entered for that mailbox. No session cookies, OAuth tokens, multi-factor authentication (MFA) codes, or browser sessions are exfiltrated.

    The development also follows the takedown of the Kratos (formerly Sneaky 2FA) phishing-as-a-service (PhaaS) kit by German authorities in collaboration with the U.S. and Indonesia, in addition to the arrest of its alleged developer and technical administrator. The operation is estimated to have earned more than €300,000 ($342,000) since 2024. More than 1,800 criminal enterprises are believed to have used Kratos, resulting in around 15,000 phishing campaigns per month.

    BlueDash deploys fake level operation RMM ScreenConnect teams Update
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleOpinion | A Setback for the MAGA Media Takeover
    Next Article Trump Backs New Talks but It’s Unclear What He Hopes to Achieve This Time
    admin
    • Website

    Related Posts

    Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

    July 27, 2026

    NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

    July 27, 2026

    Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

    July 27, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Lawyers, teachers, and students face consequences when they use AI to do their jobs. What about politicians?

    Trump Backs New Talks but It’s Unclear What He Hopes to Achieve This Time

    Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

    Opinion | A Setback for the MAGA Media Takeover

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by