Find notable cyber news and cases, enriched with sources, timelines, and signals.

Operation BlueDash Microsoft Teams phishing campaign delivering Level RMM and ScreenConnect

Campaign
First reported
Last updated
Happening score
H score 45
1 unique sources, 1 articles

Summary

Hide ▲

The Operation BlueDash phishing campaign is using a fake Microsoft Teams update flow to install Level RMM and ConnectWise ScreenConnect, creating persistent remote-access risk on compromised hosts. The campaign uses compromised web infrastructure, a counterfeit Microsoft Store page at teamvem[.]com, and a loader named supportdev.exe to deploy the tools. Analysts tied the activity with moderate-to-high confidence to a Nigeria-based threat-actor group and found evidence that it has been active since at least February 2026. Related infrastructure also shows a Zoom lure and other remote-management payloads, indicating a multi-brand access operation designed to survive tool removal.

Related Happenings

SeasonalInvite eCard phishing campaign targeting Windows and macOS users

Campaign
H score30 First: 15.07.2026 18:00 Last: 15.07.2026 18:00 Sources 1

About this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...

KongTuke ClickFix and Teams access-seeking campaign

Campaign
H score33 First: 25.06.2026 11:54 Last: 25.06.2026 11:54 Sources 1

About this happening: The KongTuke operation is using ClickFix lures and Microsoft Teams messages to widen access-seeking attacks against multiple organizations, increasing the risk of...

Sapphire Sleet Mastra npm supply-chain campaign

Campaign
H score42 First: 20.06.2026 17:09 Last: 20.06.2026 17:09 Sources 1

About this happening: The Mastra AI supply-chain campaign was attributed to Sapphire Sleet / BlueNoroff after Microsoft said the operation compromised the npm maintainer account "ehindero...

Atlas RAT and related loaders deployed for remote access and credential theft

Malware Activity
H score33 First: 04.06.2026 00:45 Last: 04.06.2026 00:45 Sources 1

About this happening: TA4922, a China-linked and likely financially motivated malware activity, has expanded beyond East Asia into Europe and Africa. The group uses Atlas RAT*...

JINX-0164 cryptocurrency recruitment-lure campaign

Campaign
H score39 First: 28.05.2026 10:54 Last: 28.05.2026 10:54 Sources 1

About this happening: A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...

Timeline

  1. 27.07.2026 15:37 2 articles · 3h ago

    Operation BlueDash Microsoft Teams phishing campaign delivering Level RMM and ScreenConnect

    Initial Disclosure

    The earliest observed phase used a Microsoft Teams-themed lure and a counterfeit Microsoft Store page to push a fake update before the shared document could be opened. That initial delivery chain later expanded into a multi-brand operation that reused the same infrastructure to distribute remote-management tooling.

    Show sources