Operation BlueDash: Fake Microsoft Teams Update Deploys Dual RMM Backdoors (Level RMM + ScreenConnect) — Threadlinqs Intelligence
As of 2026-07-28, Operation BlueDash: Fake Microsoft Teams Update Deploys Dual RMM Backdoors (Level RMM + ScreenConnect) is a high-severity malware threat attributed to a Nigeria-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1732 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Updated: 2026-07-28 · revalidated 1× · latest source
Attribution: Nigeria · FINANCIAL
Tracked as Operation BlueDash by ZeroBEC Team, a phishing campaign lures victims with 'document too large, shared via Teams' emails that route through compromised sites to a spoofed Microsoft Store
Operation BlueDash begins with an email claiming a document was 'too large' to send directly and was instead shared securely through Microsoft Teams. Clicking through routes the victim via compromised web infrastructure to a counterfeit Microsoft Store page — complete with Teams branding, screenshots, and a spoofed Windows taskbar — that claims Teams must be updated before the document can be opened. The 'Update' button delivers supportdev.exe, an Inno Setup-based loader hosted on infrastructure tied to the domain teamvem[.]com.
On execution, supportdev.exe silently launches PowerShell in a hidden window. That PowerShell chain fetches an official (legitimately signed) Level RMM installer and registers the endpoint using an attacker-controlled enrollment secret (LEVEL_API_KEY=GxSCHE8EZwfyYN3iPQHPai8D) with no user prompt or approval, then separately downloads and deploys ConnectWise ScreenConnect in parallel as a second, redundant remote-access channel — so losing one tool does not cost the operator access. Once remote control is established, operators run hands-on-keyboard reconnaissance: whether the host needs a reboot, whether BitLocker disk encryption is active, how the host firewall is configured, and who belongs to (and what the local Administrators group is named as) the local Administrators group — recon consistent with preparing for further lateral movement, credential access, or ransomware-affiliate-style follow-on activity rather than opportunistic, automated malware.
ZeroBEC's investigation traced the phishing infrastructure to a GitHub account ('berry4603') operating at least two repositories: 'Bluedashltd' — containing the phishing page source, a CNAME record pointing at the teamvem[.]com/berry4603.github[.]io infrastructure, and the supportdev.exe payload itself, with commit history dating to at least February 2026 — and a second repository, 'rustovni', hosting a parallel Zoom-meeting-themed lure. That Zoom variant fetches the Tactical RMM agent directly from its official GitHub release, installs it to the Windows temporary directory, and self-registers the host using an embedded authentication token — the same dual-RMM, living-off-trusted-software playbook applied to a different meeting-app brand and a third RMM product. Additional attacker-support infrastructure was identified at support[.]berrydev[.]xyz, though no BeaconBeagle C2 correlation records exist for either that domain or teamvem[.]com as of this research.
ZeroBEC attributes the campaign, with moderate-to-high confidence, to a Nigeria-based actor based on infrastructure reuse, GitHub commit/code history, and the operator's development environment fingerprints; the group has not been given a named designation beyond the Operation BlueDash campaign tracker. The Hacker News and Cyber Security News independently corroborated the reporting on 2026-07-27. This is one of several recent campaigns abusing legitimate RMM software as a phishing payload — Microsoft separately documented an unrelated February 2026 cluster (certificate-signed installers impersonating Teams/Zoom/Adobe/Meet, deploying ScreenConnect + Tactical RMM + MeshAgent via trustconnectsoftware[.]com/pacdashed[.]com infrastructure) and other researchers have documented daisy-chained RMM abuse via Action1, HeartbeatRM, ITarian, PDQ, SimpleHelp, and Atera. These are tracked as distinct incidents/infrastructure from Operation BlueDash and their IOCs are not asserted to overlap with it, but they establish RMM-as-backdoor as an active, broader TTP trend worth building durable detection coverage against.
Detections & IOCs
As of 2026-08-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583, T1584, T1189, T1566, T1204, T1059, T1547, T1564, T1036, T1553