Threat reportMalwareTL-2026-1732

Operation BlueDash: Fake Microsoft Teams Update Deploys Dual RMM Backdoors (Level RMM + ScreenConnect)

highACTIVE

Operation BlueDash (TL-2026-1732), also tracked as Operation BlueDash, is a high-severity malware campaign, first published 2026-07-27 and last reviewed 2026-07-28. It is linked to a Nigeria-nexus actor with medium confidence, affects Level RMM Level RMM endpoint enrollment/agent, maps to 19 MITRE ATT&CK techniques (T1036, T1059, T1069), and is covered by 9 detection rules and 27 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
19MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
27Indicators of compromise

Key facts for TL-2026-1732

Threat ID
TL-2026-1732
Also known as
Operation BlueDash, BlueDash
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
MEDIUM
Nation-state nexus
Nigeria
Motivation
FINANCIAL
Detection rules
9
Indicators of compromise
27
Updates
2026-07-28 · revalidated 1× · latest source

Malware and tooling in Operation BlueDash

Malware and tooling: Inno Setup, Level RMM, ScreenConnect, Tactical RMM

How Operation BlueDash works

Tracked as Operation BlueDash by ZeroBEC Team, a phishing campaign lures victims with 'document too large, shared via Teams' emails that route through compromised sites to a spoofed Microsoft Store page; the fake 'Update' downloads supportdev.exe, an Inno Setup package that silently launches hidden PowerShell to install two redundant remote-access tools (Level RMM via a hardcoded enrollment key, plus ConnectWise ScreenConnect) with no user approval, followed by post-compromise recon of BitLocker, firewall, and admin-group state.

Operation BlueDash begins with an email claiming a document was 'too large' to send directly and was instead shared securely through Microsoft Teams. Clicking through routes the victim via compromised web infrastructure to a counterfeit Microsoft Store page — complete with Teams branding, screenshots, and a spoofed Windows taskbar — that claims Teams must be updated before the document can be opened. The 'Update' button delivers supportdev.exe, an Inno Setup-based loader hosted on infrastructure tied to the domain teamvem[.]com.

On execution, supportdev.exe silently launches PowerShell in a hidden window. That PowerShell chain fetches an official (legitimately signed) Level RMM installer and registers the endpoint using an attacker-controlled enrollment secret (LEVEL_API_KEY=GxSCHE8EZwfyYN3iPQHPai8D) with no user prompt or approval, then separately downloads and deploys ConnectWise ScreenConnect in parallel as a second, redundant remote-access channel — so losing one tool does not cost the operator access. Once remote control is established, operators run hands-on-keyboard reconnaissance: whether the host needs a reboot, whether BitLocker disk encryption is active, how the host firewall is configured, and who belongs to (and what the local Administrators group is named as) the local Administrators group — recon consistent with preparing for further lateral movement, credential access, or ransomware-affiliate-style follow-on activity rather than opportunistic, automated malware.

ZeroBEC's investigation traced the phishing infrastructure to a GitHub account ('berry4603') operating at least two repositories: 'Bluedashltd' — containing the phishing page source, a CNAME record pointing at the teamvem[.]com/berry4603.github[.]io infrastructure, and the supportdev.exe payload itself, with commit history dating to at least February 2026 — and a second repository, 'rustovni', hosting a parallel Zoom-meeting-themed lure. That Zoom variant fetches the Tactical RMM agent directly from its official GitHub release, installs it to the Windows temporary directory, and self-registers the host using an embedded authentication token — the same dual-RMM, living-off-trusted-software playbook applied to a different meeting-app brand and a third RMM product. Additional attacker-support infrastructure was identified at support[.]berrydev[.]xyz, though no BeaconBeagle C2 correlation records exist for either that domain or teamvem[.]com as of this research.

ZeroBEC attributes the campaign, with moderate-to-high confidence, to a Nigeria-based actor based on infrastructure reuse, GitHub commit/code history, and the operator's development environment fingerprints; the group has not been given a named designation beyond the Operation BlueDash campaign tracker. The Hacker News and Cyber Security News independently corroborated the reporting on 2026-07-27. This is one of several recent campaigns abusing legitimate RMM software as a phishing payload — Microsoft separately documented an unrelated February 2026 cluster (certificate-signed installers impersonating Teams/Zoom/Adobe/Meet, deploying ScreenConnect + Tactical RMM + MeshAgent via trustconnectsoftware[.]com/pacdashed[.]com infrastructure) and other researchers have documented daisy-chained RMM abuse via Action1, HeartbeatRM, ITarian, PDQ, SimpleHelp, and Atera. These are tracked as distinct incidents/infrastructure from Operation BlueDash and their IOCs are not asserted to overlap with it, but they establish RMM-as-backdoor as an active, broader TTP trend worth building durable detection coverage against.

MITRE ATT&CK techniques used in TL-2026-1732

Defense Evasion

T1036 Masquerading; T1564 Hide Artifacts

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Discovery

T1069 Permission Groups Discovery; T1082 System Information Discovery; T1087 Account Discovery; T1518 Software Discovery

Command and Control

T1105 Ingress Tool Transfer; T1219 Remote Access Tools

Persistence

T1133 External Remote Services; T1547 Boot or Logon Autostart Execution

Initial Access

T1189 Drive-by Compromise; T1566 Phishing

defense-impairment

T1553 Subvert Trust Controls

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1588 Obtain Capabilities; T1608 Stage Capabilities

Affected products and versions in Operation BlueDash

  • Level RMM — Level RMM endpoint enrollment/agent
    Vulnerable versions: N/A – legitimate enrollment feature abused via a hardcoded API key, not a software vulnerability
    Fixed in: N/A
  • ConnectWise — ScreenConnect
    Vulnerable versions: N/A – legitimate remote-access client deployed as an unauthorized redundant backdoor
    Fixed in: N/A
  • Tactical RMM — Tactical RMM agent
    Vulnerable versions: N/A – official GitHub-release agent installed via an embedded self-registration token (Zoom-lure variant)
    Fixed in: N/A
  • Microsoft — Microsoft Teams / Microsoft Store (brand and UI impersonated)
    Vulnerable versions: N/A – brand/UI impersonation used as a phishing lure, not a vulnerable product version
    Fixed in: N/A

Remediation for Operation BlueDash

Patches

  • Not applicable — the campaign abuses legitimate RMM enrollment/deployment functionality and social engineering rather than a software vulnerability; no vendor patch remediates the underlying exposure

Immediate actions

  • Block/deny outbound resolution and connections to teamvem[.]com, support.berrydev[.]xyz, and berry4603.github[.]io at DNS resolvers, web proxies, and the email gateway
  • Hunt EDR/endpoint telemetry for supportdev.exe, unexpected Level RMM or ConnectWise ScreenConnect installers, and unapproved Tactical RMM agents in %TEMP%; isolate and reimage any confirmed host
  • Revoke/rotate the exposed Level RMM enrollment key (LEVEL_API_KEY=GxSCHE8EZwfyYN3iPQHPai8D) and audit the Level RMM tenant for any endpoint enrolled through it
  • Hunt for PowerShell processes launched with a hidden window style (-WindowStyle Hidden) spawned as a child of an Inno Setup installer process

Workarounds

  • Restrict Microsoft Teams update prompts to the in-app/MSI updater only; block direct browser downloads of Teams-branded executables
  • Require ticket-linked, multi-party approval for any new RMM endpoint enrollment to prevent silent, unapproved registrations

Longer-term hardening

  • Maintain an explicit RMM allowlist (approved tools only) and alert on installation of any RMM client — Level RMM, ScreenConnect, Tactical RMM, MeshAgent, etc. — outside that list
  • Deploy application control (AppLocker/WDAC) to block installer execution from user-writable/download directories regardless of code-signing status
  • Enforce PowerShell Script Block Logging, module logging, and Constrained Language Mode to increase visibility into hidden-window PowerShell abuse
  • Run recurring user-awareness training targeting 'document shared via Teams, update required' lures and fake Microsoft Store update pages

Timeline of Operation BlueDash

  • Commit history for the GitHub-hosted phishing repositories ('Bluedashltd' and 'rustovni', account berry4603) begins, indicating Operation BlueDash's supporting infrastructure was operational by at least early February 2026.
  • Cyber Security News and The Hacker News independently publish corroborating reports crediting ZeroBEC Team's findings.
  • ZeroBEC Team attributes the campaign, with moderate-to-high confidence, to a Nigeria-based actor based on infrastructure, code history, and GitHub development-environment analysis, naming it Operation BlueDash.
  • A parallel Zoom-meeting-themed variant using the 'rustovni' repository is identified, delivering the Tactical RMM agent from its official GitHub release into the Windows temp directory with an embedded self-registration auth token.
  • Operators run hands-on-keyboard host reconnaissance: reboot-required status, BitLocker encryption state, firewall configuration, and local Administrators group membership/naming.
  • The hidden PowerShell chain installs Level RMM using a hardcoded enrollment key (LEVEL_API_KEY=GxSCHE8EZwfyYN3iPQHPai8D) with no user approval, and deploys ConnectWise ScreenConnect in parallel as a redundant access channel.
  • Victims download and run supportdev.exe, an Inno Setup package that silently launches a hidden PowerShell window.
  • Phishing emails claiming a Teams-shared document is 'too large' are observed circulating, routing victims through compromised websites to a spoofed Microsoft Store update page at teamvem[.]com.
  • GBHackers News publishes 'Operation BlueDash Maintains Redundant Remote Access Even After One RMM Tool Is Removed,' citing ZeroBEC research and detailing 9 confirmed IOC domains including newly identified redirectors and the Zoom-variant Tactical RMM infrastructure.
  • ZeroBEC publishes its original research report 'Operation BlueDash: multi-RMM workplace phishing,' the primary technical source underlying prior news coverage.

Update history for TL-2026-1732

Sources cited for Operation BlueDash

Detection coverage for TL-2026-1732

As of 2026-07-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1732 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
27 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats