Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
A coordinated phishing campaign dubbed Operation BlueDash is leveraging fake Microsoft Teams updates to gain remote control over corporate systems.
Questions people are asking
What is Operation BlueDash?
It is a phishing campaign that distributes malicious remote management software under the guise of fake Microsoft Teams updates.
Which tools are being deployed by the attackers?
The campaign utilizes Level RMM, ScreenConnect, and Tactical RMM to gain control over affected computers.
How are victims being targeted?
Attackers are using vishing to impersonate IT support, often directing users toward fraudulent software updates.
What happened
Operation BlueDash targets corporate users by masquerading as legitimate Microsoft Teams updates to deploy remote monitoring and management tools, specifically Level RMM, ScreenConnect, and Tactical RMM. Microsoft has detected 7.6 billion email phishing threats, with the current trend showing a 10-fold increase in vishing attacks centered on impersonating IT support staff.
Once an unsuspecting user interacts with the fraudulent update, attackers secure two distinct methods for gaining unauthorized control over the host machine. CyberSecurityNews, gbhackers.com, The Hacker News, and cyberpress.org note that these attackers aim to steal corporate access.
The specific technical progression involves initial contact via vishing, followed by the deployment of persistent remote access software. Monitoring of future threat actor activity remains focused on how organizations adjust security protocols to mitigate these impersonation tactics.
Synthesized by headlinez.news from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 2h ago.
Sources (5)
- Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold CyberSecurityNews · 1d ago
- Operation BlueDash Phishing Campaign Deploys Level RMM, ScreenConnect and Tactical RMM cyberpress.org · 1d ago
- Attackers Abuse Microsoft Teams to Impersonate IT Support and Steal Corporate Access gbhackers.com · 1d ago
- A Fake Teams Update Can Give Hackers Two Separate Ways to Control Your PC CyberSecurityNews · 1d ago
- Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update The Hacker News · 1d ago
How fast it spread
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
Topics
From around our network
Related trends
Hugging Face wants $100mn of compute from OpenAI
Hugging Face is seeking $100 million in compute resources from OpenAI following a series of significant security breaches across the AI industry.
Ariana Grande Sues Over Yearslong Hacking Campaign Targeting Inner Circle
Ariana Grande has filed a lawsuit regarding a yearslong hacking campaign that reportedly compromised her private files and unreleased music.
Samsung teases Android XR glasses with phone & watch integration, ‘reasonable’ price
Samsung's upcoming Android XR glasses promise integrated device connectivity, prompting industry scrutiny regarding potential corporate security risks.
Apple Releases iOS 26.6 and iPadOS 26.6 With iOS 27 Optimizations
Apple has launched iOS 26.6 and macOS 26.6, introducing wide-reaching security patches and system optimizations ahead of upcoming software releases.
Angelina Jolie and Robert De Niro at centre of contact detail ‘leak’
Angelina Jolie, Robert De Niro, and other prominent Hollywood figures are identified as victims of a significant cyberattack involving private data exposure.
Microsoft Unveils A.I. Cybersecurity Tools
Microsoft has introduced a suite of homegrown AI tools and agentic systems designed to preemptively identify and address cybersecurity vulnerabilities.