Researchers reported that Operation BlueDash is using Microsoft Teams-themed phishing lures to trick users into installing legitimate remote monitoring and management (RMM) software, giving attackers persistent remote access while blending into normal enterprise administration. Victims are redirected through compromised infrastructure to a fake Microsoft Store page at teamvem[.]com, where an Inno Setup loader named supportdev.exe launches hidden PowerShell to retrieve and register Level RMM and, in some cases, ConnectWise ScreenConnect. Investigators linked the activity with moderate-to-high confidence to a Nigeria-based threat actor and identified supporting GitHub infrastructure, including the Bluedashltd repository and berry4603.github[.]io, indicating the campaign has been active since at least February 2026.
The campaign reflects a broader pattern in which adversaries abuse legitimate RMM tools because they provide powerful remote administration capabilities and can evade scrutiny in environments where such software is common. Security researchers have previously highlighted sustained abuse of tools such as NetSupport Manager, Atera, Remote Utilities, and Remcos, with groups including SCATTERED SPIDER using multiple RMM platforms for lateral movement and hands-on-keyboard operations. In the BlueDash activity, operators were also seen conducting host reconnaissance after access, and related infrastructure supported a parallel Zoom-themed lure chain delivering Tactical RMM, underscoring how attackers are using trusted remote-access software and multi-brand social engineering to maintain access and complicate detection.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers reported a phishing campaign dubbed Operation BlueDash that uses Microsoft Teams-themed secure-document lures and compromised infrastructure to direct victims to a fake Microsoft Store page at teamvem[.]com. The infection chain uses an Inno Setup loader named supportdev.exe to launch hidden PowerShell that installs Level RMM and sometimes ConnectWise ScreenConnect, while related infrastructure also showed a Zoom-themed lure delivering Tactical RMM.
ZeroBEC reported that infrastructure tied to Operation BlueDash, including GitHub assets such as the Bluedashltd repository and berry4603.github[.]io, indicates the campaign has been active since at least February 2026. The activity was attributed with moderate-to-high confidence to a Nigeria-based threat actor.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourcezerobec.com
Open sourceredcanary.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.