Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
Fake Microsoft Teams updates let attackers install dual remote‑control tools, sparking a wave of corporate compromises under Operation BlueDash.
Questions people are asking
What is Operation BlueDash?
Operation BlueDash is a phishing campaign that uses counterfeit Microsoft Teams update prompts to deliver remote‑management tools such as Level RMM, ScreenConnect and the GoGRPC backdoor, according to coverage from multiple security outlets.
Which tools are being installed by the fake Teams update?
The malicious update drops two remote‑management platforms—Level RMM and ScreenConnect—as well as the GoGRPC backdoor that provides persistent proxy access, as reported by The Hacker News and cyberpress.org.
How are victims being coerced into installing the malicious update?
Attackers impersonate IT support through phishing emails and vishing calls, sometimes hijacking Quick Assist sessions to persuade users to run the fake Teams installer, per reports from Sophos, gbhackers.com and Hackread.
What happened
Hackers can achieve dual control of a compromised PC via a fake Microsoft Teams update, as detailed by The Hacker News. The update installs two remote‑management tools—Level RMM and ScreenConnect—while also dropping the GoGRPC backdoor. The technique is linked to the Operation BlueDash phishing campaign, which fabricates Teams‑update prompts to lure users into granting elevated access. The campaign blends phishing emails that impersonate IT support with vishing phone calls, a pattern described by Sophos and gbhackers.com.
Victims are directed to open a malicious Teams installer or to share screen via Quick Assist, enabling attackers to hijack sessions and install persistent backdoors, as reported by cyberpress.org and Hackread. Microsoft’s telemetry flagged 7.6 billion phishing messages tied to the surge, underscoring the scale of the threat. Security teams are advised to scrutinize any unsolicited Teams update prompts and to verify IT requests through independent channels, per guidance from CyberSecurityNews. Enterprises should also reinforce multi‑factor authentication for remote‑access tools and monitor for abnormal RMM traffic.
Watch for further alerts from Microsoft and for additional Windows‑based ransomware payloads that may piggyback on the same infection chain. The ongoing cyber‑intelligence feeds suggest that attackers may adapt the fake‑update vector to other collaboration platforms, making timely patch management critical.
Synthesized by headlinez.news from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 49d ago.
Sources (8)
- Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections Hackread · 51d ago
- Chaos in Teams vishing Sophos · 51d ago
- Helpdesk Hijackers Turn Quick Assist Sessions Into Persistent Backdoor and Proxy Access cyberpress.org · 51d ago
- Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold CyberSecurityNews · 51d ago
- Operation BlueDash Phishing Campaign Deploys Level RMM, ScreenConnect and Tactical RMM cyberpress.org · 51d ago
- Attackers Abuse Microsoft Teams to Impersonate IT Support and Steal Corporate Access gbhackers.com · 51d ago
- A Fake Teams Update Can Give Hackers Two Separate Ways to Control Your PC CyberSecurityNews · 51d ago
- Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update The Hacker News · 51d ago
How fast it spread
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
Topics
Related trends
Preview: Playing Final Fantasy VII: Revelation On PS5 Has Me Worried For The Switch 2 Port
At Gamescom 2026, hands-on previews of Final Fantasy VII Revelation revealed a sprawling, high-flying conclusion—and mounting anxiety over bloat.
Major Kingdom Hearts 4 leak surfaces, new worlds revealed
A massive Steam maintenance bug has exposed unreleased Kingdom Hearts 4 achievements, laying bare a sprawling list of unexpected worlds.
Ghost of Yotei: Complete Edition's Most Wanted roguelike mode brings back Tsushima's Jin Sakai
Jin Sakai crosses centuries to join Ghost of Yōtei's upcoming roguelike mode, bringing his complete Tsushima arsenal along for the hunt.
Capcom quietly releases new trailers for Monster Hunter Wilds Ascendance, teasing changes to all 14 weapon types
Capcom’s silent rollout of daily weapon teasers reveals a game‑changing Boost Bracer just days before TGS.
Final Fantasy VII Revelation ‘The Planet’s Crisis’ trailer, screenshots
Square Enix drops the final FFVII remake trailer, promising brutal Weapon duels and an air‑ship you can actually jump out of.
Warlock: Dungeons & Dragons gameplay reveal trailer, screenshots
Warlock’s Gamescom trailer shows a spell‑slinging lone hero, signaling Wizards of the Coast’s bold leap into AAA single‑player action.