Operation BlueDash Exploits Fake Microsoft Teams Updates to Deploy RMM Tools
A phishing campaign exploiting fake Microsoft Teams updates delivers RMM tools like Level RMM and ScreenConnect to compromise endpoints, with threat actors linked to Nigeria using multi-stage payloads for persistent access. The attack highlights the use of legitimate RMM platforms for malicious purposes and ties to broader phishing operations targeting enterprise environments.
Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) tools.
"The victim was directed through compromised web infrastructure to a counterfeit Microsoft Store page claiming that Microsoft Teams had to be updated before the shared document could be opened," ZeroBEC said in
*** END OF TRANSMISSION ***