At a glance: Attackers deploy fake Microsoft Teams updates to trick victims into downloading Level RMM and ScreenConnect, compromising their systems.
Cybersecurity researchers have documented a phishing campaign that exploits a Microsoft Teams update deception to distribute legitimate remote management tools as malware. Attackers redirect victims through manipulated web infrastructure to fraudulent Microsoft Store pages.
ZeroBEC researchers describe the campaign “Operation BlueDash” as a targeted phishing operation that uses a “secure document” notification as bait. The scheme operates on a simple pattern: victims are told they want to open a shared document, but then see a message stating that Microsoft Teams must be updated first.
The redirect flows through compromised web servers to a visually authentic Microsoft Store page. There, victims are prompted to download RMM tools (Remote Monitoring and Management) – specifically Level RMM and ScreenConnect. Since these are legitimate administration tools, they are often not blocked by antivirus systems. Attackers exploit this to gain persistent access to affected systems.
For CISOs, this campaign is relevant because it combines multiple proven social engineering techniques: (1) trust hijacking through abuse of a well-known platform, (2) sense of urgency through update notification, and (3) legitimacy spoofing through fake official stores. Particularly insidious is the use of genuine RMM tools, which can easily circumvent Endpoint Detection and Response (EDR) and traditional signature-based security.
Recommended measures: training on phishing indicators (suspicious download requests for known software), implementation of URL filtering and reputation checking, restriction of RMM tool installations to whitelisted versions with verified digital signatures, and monitoring of unexpected RMM activity on the network.
Source: thehackernews.com · Published 27 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.