Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
A coordinated phishing campaign dubbed Operation BlueDash is utilizing fraudulent Microsoft Teams updates to gain unauthorized remote control of corporate computers.
Questions people are asking
What is Operation BlueDash?
It is a phishing campaign that distributes Level RMM, Tactical RMM, and ScreenConnect by masquerading as a fake Microsoft Teams update.
How do the attackers gain access?
Attackers impersonate IT support via vishing to convince users to install malicious updates, which then grant the intruders remote control over the target's PC.
Are there trends in the volume of these threats?
Microsoft data indicates a 10-fold increase in Teams-based vishing attacks and identifies 7.6 billion email phishing threats.
What happened
Microsoft has detected 7.6 billion email phishing threats while noting a 10-fold increase in vishing attacks targeting Microsoft Teams. Under the banner of Operation BlueDash, attackers are impersonating IT support staff to deceive users into installing fake software updates. These malicious updates facilitate the unauthorized deployment of remote monitoring and management tools, specifically Level RMM, Tactical RMM, and ScreenConnect.
This vector provides hackers with two distinct methods to establish persistent control over compromised corporate PCs. CyberSecurityNews, cyberpress.org, gbhackers.com, and The Hacker News report that these intrusions enable the theft of corporate access credentials. Because the attack masks itself as a routine update process, individuals are susceptible to granting attackers broad administrative privileges.
Coverage does not yet specify the geographic scope of the campaign or the specific organizations currently impacted by these remote access tools.
Synthesized by Newsylist from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 2h ago.
Sources (5)
- Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold CyberSecurityNews · 1d ago
- Operation BlueDash Phishing Campaign Deploys Level RMM, ScreenConnect and Tactical RMM cyberpress.org · 1d ago
- Attackers Abuse Microsoft Teams to Impersonate IT Support and Steal Corporate Access gbhackers.com · 1d ago
- A Fake Teams Update Can Give Hackers Two Separate Ways to Control Your PC CyberSecurityNews · 1d ago
- Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update The Hacker News · 1d ago broke it first
How fast it spread
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
People, places & organizations
Topics
From around our network
Related trends
Ariana Grande sues hackers who leaked music and videos
Ariana Grande has initiated legal action against unknown hackers responsible for the unauthorized distribution of her private music, photos, and video footage.
Hugging Face wants $100mn of compute from OpenAI
Hugging Face is seeking $100 million in compute resources from OpenAI following a significant security breach involving its platform.
Ariana Grande Sues Over Yearslong Hacking Campaign Targeting Inner Circle
Ariana Grande has filed a lawsuit against alleged hackers following a yearslong campaign targeting her inner circle and leaking unreleased music.
Microsoft launches its first cybersecurity model, plus a new agentic cybersecurity system
Microsoft is challenging industry leaders with a new in-house cybersecurity AI model and an agentic system designed to lower costs.
Microsoft Unveils A.I. Cybersecurity Tools
Microsoft is entering the "agentic era" of security with the launch of its first homegrown AI model and new cybersecurity tools.
Angelina Jolie and Robert De Niro at centre of contact detail ‘leak’
Private contact information for high-profile figures including Angelina Jolie and Robert De Niro has been exposed in a cyberattack.