Operation BlueDash Microsoft Teams phishing campaign delivering Level RMM and ScreenConnect
Campaign
Summary
Hide ▲
Show ▼
The Operation BlueDash phishing campaign is using a fake Microsoft Teams update flow to install Level RMM and ConnectWise ScreenConnect, creating persistent remote-access risk on compromised hosts. The campaign uses compromised web infrastructure, a counterfeit Microsoft Store page at teamvem[.]com, and a loader named supportdev.exe to deploy the tools. Analysts tied the activity with moderate-to-high confidence to a Nigeria-based threat-actor group and found evidence that it has been active since at least February 2026. Related infrastructure also shows a Zoom lure and other remote-management payloads, indicating a multi-brand access operation designed to survive tool removal.
Related Happenings
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
Campaign
H score30
First: 15.07.2026 18:00
Last: 15.07.2026 18:00
Sources 1
About this happening:
The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
CampaignAbout this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...
KongTuke ClickFix and Teams access-seeking campaign
Campaign
H score33
First: 25.06.2026 11:54
Last: 25.06.2026 11:54
Sources 1
About this happening:
The KongTuke operation is using ClickFix lures and Microsoft Teams messages to widen access-seeking attacks against multiple organizations, increasing the risk of...
KongTuke ClickFix and Teams access-seeking campaign
CampaignAbout this happening: The KongTuke operation is using ClickFix lures and Microsoft Teams messages to widen access-seeking attacks against multiple organizations, increasing the risk of...
Sapphire Sleet Mastra npm supply-chain campaign
Campaign
H score42
First: 20.06.2026 17:09
Last: 20.06.2026 17:09
Sources 1
About this happening:
The Mastra AI supply-chain campaign was attributed to Sapphire Sleet / BlueNoroff after Microsoft said the operation compromised the npm maintainer account "ehindero...
Sapphire Sleet Mastra npm supply-chain campaign
CampaignAbout this happening: The Mastra AI supply-chain campaign was attributed to Sapphire Sleet / BlueNoroff after Microsoft said the operation compromised the npm maintainer account "ehindero...
Atlas RAT and related loaders deployed for remote access and credential theft
Malware Activity
H score33
First: 04.06.2026 00:45
Last: 04.06.2026 00:45
Sources 1
About this happening:
TA4922, a China-linked and likely financially motivated malware activity, has expanded beyond East Asia into Europe and Africa. The group uses Atlas RAT*...
Atlas RAT and related loaders deployed for remote access and credential theft
Malware ActivityAbout this happening: TA4922, a China-linked and likely financially motivated malware activity, has expanded beyond East Asia into Europe and Africa. The group uses Atlas RAT*...
JINX-0164 cryptocurrency recruitment-lure campaign
Campaign
H score39
First: 28.05.2026 10:54
Last: 28.05.2026 10:54
Sources 1
About this happening:
A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...
JINX-0164 cryptocurrency recruitment-lure campaign
CampaignAbout this happening: A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...
Timeline
-
27.07.2026 15:37 2 articles · 3h ago
Operation BlueDash Microsoft Teams phishing campaign delivering Level RMM and ScreenConnect
Initial DisclosureThe earliest observed phase used a Microsoft Teams-themed lure and a counterfeit Microsoft Store page to push a fake update before the shared document could be opened. That initial delivery chain later expanded into a multi-brand operation that reused the same infrastructure to distribute remote-management tooling.
Show sources
- Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update — thehackernews.com — 27.07.2026 15:37
- Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update — thehackernews.com — 27.07.2026 15:37