Operation BlueDash Uses Fake Microsoft Teams Updates To Deploy Remote Access Tools

Published:

Cybersecurity researchers have uncovered a Microsoft Teams themed phishing campaign known as Operation BlueDash that uses fake software update pages to install legitimate remote monitoring and management tools on Windows systems. According to a report published by ZeroBEC, the campaign begins with phishing emails containing secure document lures that direct victims through compromised web infrastructure to a counterfeit Microsoft Store page. The fake page claims that Microsoft Teams must be updated before the shared document can be accessed. Researchers identified one such fraudulent website operating under the domain teamvem[.]com, where victims are prompted to download a malicious file disguised as a Teams update. Although the downloaded application appears legitimate, it is actually designed to install remote access software that allows attackers to maintain long term control over compromised devices.

ZeroBEC said the downloaded file, identified as supportdev.exe, functions as an Inno Setup based loader that silently launches PowerShell in a hidden window. The script downloads the official Level RMM installer and registers the infected system using an attacker controlled enrollment secret. Researchers also found that the same PowerShell command installs ConnectWise ScreenConnect at the same time, allowing attackers to deploy multiple remote monitoring and management tools simultaneously. The use of legitimate software helps the campaign avoid raising suspicion while providing persistent remote access to compromised systems. Security researchers noted that cybercriminals have increasingly abused legitimate remote administration tools because they blend into normal enterprise environments and are less likely to trigger security alerts compared to traditional malware. Earlier this year, Microsoft warned of phishing campaigns that used workplace meeting invitations and PDF attachments to distribute TrustConnect malware, which later installed ScreenConnect along with Tactical RMM and MeshAgent. ZeroBEC also documented a similar phishing operation in May 2026 that relied on secure document themed emails to deploy remote access backdoors.

Researchers attributed Operation BlueDash with moderate to high confidence to a threat actor believed to be operating from Nigeria based on its infrastructure, source code history, and GitHub environment used to support the campaign. According to ZeroBEC, attackers deploy multiple remote management platforms on the same device to ensure continued access if one of the tools is detected or removed by defenders. After establishing remote connectivity, the operators execute several reconnaissance commands to assess the condition of the compromised system. These commands determine whether the device requires a reboot, identify the status of system volume protection, review active firewall profiles, enumerate members of the local Administrators group, and identify the local administrator group name. Researchers explained that these activities reflect a structured operational process in which attackers first evaluate the security posture of the compromised device before deciding how to proceed. Because these commands originate from unauthorized remote management software rather than approved administrative tools, they also provide defenders with behavioral indicators that can help identify malicious activity.

Further analysis of the campaign infrastructure revealed additional attacker resources, including the domain support[.]berrydev[.]xyz, a GitHub Pages site, and a repository named Bluedashltd containing phishing page source code, configuration files, and malware payloads. Commit history indicates the operation has been active since at least February 2026. Researchers also identified another repository linked to the same GitHub account that hosted a Zoom themed phishing campaign designed to install Tactical RMM using an embedded authentication token. The findings suggest that the operators maintain a multi brand phishing strategy that changes workplace application themes while using the same underlying attack methods. Separately, ZeroBEC disclosed details of JIVS PhishKit, a credential harvesting campaign targeting Microsoft 365, Google Workspace, cPanel, Roundcube, Zimbra, and other email platforms through a generic phishing page. The company also noted recent international law enforcement action against the Kratos phishing as a service platform, which authorities believe was used by more than 1,800 criminal groups to launch approximately 15,000 phishing campaigns each month after generating more than €300,000 since 2024.

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.

Related articles

spot_img