← Back to Feed
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
July 27, 2026 · The Hacker News · Severity: MEDIUM
Operation BlueDash is a Microsoft Teams-themed phishing campaign that delivers legitimate remote monitoring and management (RMM) tools including Level RMM and ConnectWise ScreenConnect. Victims are directed through compromised web infrastructure to a fake Microsoft Store page claiming Teams needs updating, which drops an Inno Setup loader that fetches and installs the RMM tools using attacker-controlled enrollment secrets for persistent remote access.
Key Takeaways
- Phishing campaign impersonates Microsoft Teams updates to deliver legitimate RMM tools (Level RMM and ScreenConnect).
- Victims are directed through compromised web infrastructure to a counterfeit Microsoft Store page.
- The Inno Setup loader runs PowerShell in a hidden window to fetch and register RMM tools with attacker-controlled secrets.