In short: Operation BlueDash uses counterfeit Teams updates to install Level RMM and ConnectWise ScreenConnect, establishing redundant remote access channels.
Security researchers from ZeroBEC document an active phishing campaign in which attackers distribute two remote management tools to enterprise systems via fake Microsoft Teams updates. The infrastructure is attributed to a Nigerian-based group.
In Operation BlueDash, attackers redirect users via compromised web infrastructure to a fake Microsoft Store page under the domain teamvem.com. The page falsely claims that a software update for Microsoft Teams is required to open a supposedly shared document. The file downloaded as supportdev.exe launches the installation of the remote management tool Level RMM via PowerShell in the background and registers the system with its own key. In parallel, attackers install ConnectWise ScreenConnect to establish an additional remote access mechanism.
Following successful installation, attackers conduct systematic reconnaissance: they check system status, active firewall profiles, disk encryption status, and local administrator group members. ZeroBEC documents this sequence as the “attacker’s practical checklist”—a reconnaissance phase that determines the target scope and selection of further actions.
The campaign infrastructure is documented on GitHub under the account berry4603 and can be traced back to February 2026. An additional repository called rustovni leverages fake Zoom invitations to install Tactical RMM. ZeroBEC attributes the attacks with moderate to high confidence to a Nigeria-based group.
During the same investigation period, ZeroBEC documented the phishing kit JIVS, which has been used since August 2025 to steal credentials from enterprise email accounts. The kit targets generically Microsoft 365, Google Workspace, and other webmail providers via fake login pages on corychase.org. In parallel, German authorities in cooperation with the United States and Indonesia reported the takedown of the phishing-as-a-service operation Kratos. The service processed approximately 15,000 phishing campaigns monthly and generated revenues exceeding €300,000 since 2024.
Source: www.it-daily.net · Published 28 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.