Threat reportMalwareTL-2026-1732
Operation BlueDash: Fake Microsoft Teams Update Deploys Dual RMM Backdoors (Level RMM + ScreenConnect)
Operation BlueDash (TL-2026-1732), also tracked as Operation BlueDash, is a high-severity malware campaign, first published 2026-07-27 and last reviewed 2026-07-28. It is linked to a Nigeria-nexus actor with medium confidence, affects Level RMM Level RMM endpoint enrollment/agent, maps to 19 MITRE ATT&CK techniques (T1036, T1059, T1069), and is covered by 9 detection rules and 27 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 19MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 27Indicators of compromise
Key facts for TL-2026-1732
- Threat ID
- TL-2026-1732
- Also known as
- Operation BlueDash, BlueDash
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Nigeria
- Motivation
- FINANCIAL
- Detection rules
- 9
- Indicators of compromise
- 27
- Updates
- 2026-07-28 · revalidated 1× · latest source
Malware and tooling in Operation BlueDash
Malware and tooling: Inno Setup, Level RMM, ScreenConnect, Tactical RMM
How Operation BlueDash works
Tracked as Operation BlueDash by ZeroBEC Team, a phishing campaign lures victims with 'document too large, shared via Teams' emails that route through compromised sites to a spoofed Microsoft Store page; the fake 'Update' downloads supportdev.exe, an Inno Setup package that silently launches hidden PowerShell to install two redundant remote-access tools (Level RMM via a hardcoded enrollment key, plus ConnectWise ScreenConnect) with no user approval, followed by post-compromise recon of BitLocker, firewall, and admin-group state.
Operation BlueDash begins with an email claiming a document was 'too large' to send directly and was instead shared securely through Microsoft Teams. Clicking through routes the victim via compromised web infrastructure to a counterfeit Microsoft Store page — complete with Teams branding, screenshots, and a spoofed Windows taskbar — that claims Teams must be updated before the document can be opened. The 'Update' button delivers supportdev.exe, an Inno Setup-based loader hosted on infrastructure tied to the domain teamvem[.]com.
On execution, supportdev.exe silently launches PowerShell in a hidden window. That PowerShell chain fetches an official (legitimately signed) Level RMM installer and registers the endpoint using an attacker-controlled enrollment secret (LEVEL_API_KEY=GxSCHE8EZwfyYN3iPQHPai8D) with no user prompt or approval, then separately downloads and deploys ConnectWise ScreenConnect in parallel as a second, redundant remote-access channel — so losing one tool does not cost the operator access. Once remote control is established, operators run hands-on-keyboard reconnaissance: whether the host needs a reboot, whether BitLocker disk encryption is active, how the host firewall is configured, and who belongs to (and what the local Administrators group is named as) the local Administrators group — recon consistent with preparing for further lateral movement, credential access, or ransomware-affiliate-style follow-on activity rather than opportunistic, automated malware.
ZeroBEC's investigation traced the phishing infrastructure to a GitHub account ('berry4603') operating at least two repositories: 'Bluedashltd' — containing the phishing page source, a CNAME record pointing at the teamvem[.]com/berry4603.github[.]io infrastructure, and the supportdev.exe payload itself, with commit history dating to at least February 2026 — and a second repository, 'rustovni', hosting a parallel Zoom-meeting-themed lure. That Zoom variant fetches the Tactical RMM agent directly from its official GitHub release, installs it to the Windows temporary directory, and self-registers the host using an embedded authentication token — the same dual-RMM, living-off-trusted-software playbook applied to a different meeting-app brand and a third RMM product. Additional attacker-support infrastructure was identified at support[.]berrydev[.]xyz, though no BeaconBeagle C2 correlation records exist for either that domain or teamvem[.]com as of this research.
ZeroBEC attributes the campaign, with moderate-to-high confidence, to a Nigeria-based actor based on infrastructure reuse, GitHub commit/code history, and the operator's development environment fingerprints; the group has not been given a named designation beyond the Operation BlueDash campaign tracker. The Hacker News and Cyber Security News independently corroborated the reporting on 2026-07-27. This is one of several recent campaigns abusing legitimate RMM software as a phishing payload — Microsoft separately documented an unrelated February 2026 cluster (certificate-signed installers impersonating Teams/Zoom/Adobe/Meet, deploying ScreenConnect + Tactical RMM + MeshAgent via trustconnectsoftware[.]com/pacdashed[.]com infrastructure) and other researchers have documented daisy-chained RMM abuse via Action1, HeartbeatRM, ITarian, PDQ, SimpleHelp, and Atera. These are tracked as distinct incidents/infrastructure from Operation BlueDash and their IOCs are not asserted to overlap with it, but they establish RMM-as-backdoor as an active, broader TTP trend worth building durable detection coverage against.
MITRE ATT&CK techniques used in TL-2026-1732
Defense Evasion
T1036 Masquerading; T1564 Hide Artifacts
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Discovery
T1069 Permission Groups Discovery; T1082 System Information Discovery; T1087 Account Discovery; T1518 Software Discovery
Command and Control
T1105 Ingress Tool Transfer; T1219 Remote Access Tools
Persistence
T1133 External Remote Services; T1547 Boot or Logon Autostart Execution
Initial Access
T1189 Drive-by Compromise; T1566 Phishing
defense-impairment
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1588 Obtain Capabilities; T1608 Stage Capabilities
Affected products and versions in Operation BlueDash
- Level RMM — Level RMM endpoint enrollment/agent
Vulnerable versions: N/A – legitimate enrollment feature abused via a hardcoded API key, not a software vulnerability
Fixed in: N/A - ConnectWise — ScreenConnect
Vulnerable versions: N/A – legitimate remote-access client deployed as an unauthorized redundant backdoor
Fixed in: N/A - Tactical RMM — Tactical RMM agent
Vulnerable versions: N/A – official GitHub-release agent installed via an embedded self-registration token (Zoom-lure variant)
Fixed in: N/A - Microsoft — Microsoft Teams / Microsoft Store (brand and UI impersonated)
Vulnerable versions: N/A – brand/UI impersonation used as a phishing lure, not a vulnerable product version
Fixed in: N/A
Remediation for Operation BlueDash
Patches
- Not applicable — the campaign abuses legitimate RMM enrollment/deployment functionality and social engineering rather than a software vulnerability; no vendor patch remediates the underlying exposure
Immediate actions
- Block/deny outbound resolution and connections to teamvem[.]com, support.berrydev[.]xyz, and berry4603.github[.]io at DNS resolvers, web proxies, and the email gateway
- Hunt EDR/endpoint telemetry for supportdev.exe, unexpected Level RMM or ConnectWise ScreenConnect installers, and unapproved Tactical RMM agents in %TEMP%; isolate and reimage any confirmed host
- Revoke/rotate the exposed Level RMM enrollment key (LEVEL_API_KEY=GxSCHE8EZwfyYN3iPQHPai8D) and audit the Level RMM tenant for any endpoint enrolled through it
- Hunt for PowerShell processes launched with a hidden window style (-WindowStyle Hidden) spawned as a child of an Inno Setup installer process
Workarounds
- Restrict Microsoft Teams update prompts to the in-app/MSI updater only; block direct browser downloads of Teams-branded executables
- Require ticket-linked, multi-party approval for any new RMM endpoint enrollment to prevent silent, unapproved registrations
Longer-term hardening
- Maintain an explicit RMM allowlist (approved tools only) and alert on installation of any RMM client — Level RMM, ScreenConnect, Tactical RMM, MeshAgent, etc. — outside that list
- Deploy application control (AppLocker/WDAC) to block installer execution from user-writable/download directories regardless of code-signing status
- Enforce PowerShell Script Block Logging, module logging, and Constrained Language Mode to increase visibility into hidden-window PowerShell abuse
- Run recurring user-awareness training targeting 'document shared via Teams, update required' lures and fake Microsoft Store update pages
Timeline of Operation BlueDash
- Commit history for the GitHub-hosted phishing repositories ('Bluedashltd' and 'rustovni', account berry4603) begins, indicating Operation BlueDash's supporting infrastructure was operational by at least early February 2026.
- Cyber Security News and The Hacker News independently publish corroborating reports crediting ZeroBEC Team's findings.
- ZeroBEC Team attributes the campaign, with moderate-to-high confidence, to a Nigeria-based actor based on infrastructure, code history, and GitHub development-environment analysis, naming it Operation BlueDash.
- A parallel Zoom-meeting-themed variant using the 'rustovni' repository is identified, delivering the Tactical RMM agent from its official GitHub release into the Windows temp directory with an embedded self-registration auth token.
- Operators run hands-on-keyboard host reconnaissance: reboot-required status, BitLocker encryption state, firewall configuration, and local Administrators group membership/naming.
- The hidden PowerShell chain installs Level RMM using a hardcoded enrollment key (LEVEL_API_KEY=GxSCHE8EZwfyYN3iPQHPai8D) with no user approval, and deploys ConnectWise ScreenConnect in parallel as a redundant access channel.
- Victims download and run supportdev.exe, an Inno Setup package that silently launches a hidden PowerShell window.
- Phishing emails claiming a Teams-shared document is 'too large' are observed circulating, routing victims through compromised websites to a spoofed Microsoft Store update page at teamvem[.]com.
- GBHackers News publishes 'Operation BlueDash Maintains Redundant Remote Access Even After One RMM Tool Is Removed,' citing ZeroBEC research and detailing 9 confirmed IOC domains including newly identified redirectors and the Zoom-variant Tactical RMM infrastructure.
- ZeroBEC publishes its original research report 'Operation BlueDash: multi-RMM workplace phishing,' the primary technical source underlying prior news coverage.
Update history for TL-2026-1732
- 2026-07-28 — Operation BlueDash: Nigeria-Based Actor Deploys Dual/Redundant RMM Access (Level RMM, ScreenConnect, Tactical RMM) via Fake Microsoft Teams Update and Zoom-Themed Phishing: What changed No severity/exploitability/status escalation — both remain HIGH/ACTIVE/ACTIVE. The update substantially expands known campaign infrastructure and technical detail rather than changing risk posture. New indicators (9) 7 new doma
Sources cited for Operation BlueDash
- A Fake Teams Update Can Give Hackers Two Separate Ways to Control Your PC
- Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
- berry4603/Bluedashltd (phishing infrastructure repository)
- Signed malware impersonating workplace apps deploys RMM backdoors
- How Threat Actors Abuse Remote Management Tools (daisy-chaining rogue RMM tools)
- Threat Actors Leverage Several RMM Tools in Phishing Attack to Maintain Remote Access
Detection coverage for TL-2026-1732
As of 2026-07-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1732 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.