BlueDash Phish Uses Fake Teams Update to Install Dual RMM Tools

TL;DR Summary
BlueDash is a Nigeria-linked phishing operation that lures victims with a counterfeit Microsoft Teams update page to trigger a PowerShell-based loader, which downloads and installs multiple remote monitoring and management tools (including Level RMM and ConnectWise ScreenConnect) and registers the host with an attacker-controlled enrollment secret for persistent access; the campaign uses cross-brand lures (like Zoom) and shared infrastructure on Berrydev.xyz and GitHub Pages, and includes reconnaissance steps to map system state, firewall posture, and privileged local accounts to guide its next moves.
- Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update The Hacker News
- A Fake Teams Update Can Give Hackers Two Separate Ways to Control Your PC CyberSecurityNews
- Attackers Abuse Microsoft Teams to Impersonate IT Support and Steal Corporate Access gbhackers.com
- Operation BlueDash Phishing Campaign Deploys Level RMM, ScreenConnect and Tactical RMM cyberpress.org
- Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold CyberSecurityNews
Reading Insights
Total Reads
0
Unique Readers
35
Time Saved
4 min
vs 4 min read
Condensed
90%
795 → 83 words
Want the full story? Read the original article
Read on The Hacker News