# Operation BlueDash: Fake Microsoft Teams Update Deploys Dual RMM Backdoors (Level RMM + ScreenConnect)

> Tracked as Operation BlueDash by ZeroBEC Team, a phishing campaign lures victims with 'document too large, shared via Teams' emails that route through compromised sites to a spoofed Microsoft Store page; the fake 'Update' downloads supportdev.exe, an Inno Setup package that silently launches hidden PowerShell to install two redundant remote-access tools (Level RMM via a hardcoded enrollment key, plus ConnectWise ScreenConnect) with no user approval, followed by post-compromise recon of BitLocker, firewall, and admin-group state.

- **Published:** 2026-07-27T00:00:00Z
- **Last reviewed:** 2026-07-28T05:17:52.477Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1732
- **ID:** TL-2026-1732
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 27 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Operation BlueDash begins with an email claiming a document was 'too large' to send directly and was instead shared securely through Microsoft Teams. Clicking through routes the victim via compromised web infrastructure to a counterfeit Microsoft Store page — complete with Teams branding, screenshots, and a spoofed Windows taskbar — that claims Teams must be updated before the document can be opened. The 'Update' button delivers supportdev.exe, an Inno Setup-based loader hosted on infrastructure tied to the domain teamvem[.]com.

On execution, supportdev.exe silently launches PowerShell in a hidden window. That PowerShell chain fetches an official (legitimately signed) Level RMM installer and registers the endpoint using an attacker-controlled enrollment secret (LEVEL_API_KEY=GxSCHE8EZwfyYN3iPQHPai8D) with no user prompt or approval, then separately downloads and deploys ConnectWise ScreenConnect in parallel as a second, redundant remote-access channel — so losing one tool does not cost the operator access. Once remote control is established, operators run hands-on-keyboard reconnaissance: whether the host needs a reboot, whether BitLocker disk encryption is active, how the host firewall is configured, and who belongs to (and what the local Administrators group is named as) the local Administrators group — recon consistent with preparing for further lateral movement, credential access, or ransomware-affiliate-style follow-on activity rather than opportunistic, automated malware.

ZeroBEC's investigation traced the phishing infrastructure to a GitHub account ('berry4603') operating at least two repositories: 'Bluedashltd' — containing the phishing page source, a CNAME record pointing at the teamvem[.]com/berry4603.github[.]io infrastructure, and the supportdev.exe payload itself, with commit history dating to at least February 2026 — and a second repository, 'rustovni', hosting a parallel Zoom-meeting-themed lure. That Zoom variant fetches the Tactical RMM agent directly from its official GitHub release, installs it to the Windows temporary directory, and self-registers the host using an embedded authentication token — the same dual-RMM, living-off-trusted-software playbook applied to a different meeting-app brand and a third RMM product. Additional attacker-support infrastructure was identified at support[.]berrydev[.]xyz, though no BeaconBeagle C2 correlation records exist for either that domain or teamvem[.]com as of this research.

ZeroBEC attributes the campaign, with moderate-to-high confidence, to a Nigeria-based actor based on infrastructure reuse, GitHub commit/code history, and the operator's development environment fingerprints; the group has not been given a named designation beyond the Operation BlueDash campaign tracker. The Hacker News and Cyber Security News independently corroborated the reporting on 2026-07-27. This is one of several recent campaigns abusing legitimate RMM software as a phishing payload — Microsoft separately documented an unrelated February 2026 cluster (certificate-signed installers impersonating Teams/Zoom/Adobe/Meet, deploying ScreenConnect + Tactical RMM + MeshAgent via trustconnectsoftware[.]com/pacdashed[.]com infrastructure) and other researchers have documented daisy-chained RMM abuse via Action1, HeartbeatRM, ITarian, PDQ, SimpleHelp, and Atera. These are tracked as distinct incidents/infrastructure from Operation BlueDash and their IOCs are not asserted to overlap with it, but they establish RMM-as-backdoor as an active, broader TTP trend worth building durable detection coverage against.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1584 Compromise Infrastructure
- T1189 Drive-by Compromise
- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1547 Boot or Logon Autostart Execution
- T1564 Hide Artifacts
- T1036 Masquerading
- T1553 Subvert Trust Controls
- T1087 Account Discovery
- T1069 Permission Groups Discovery
- T1518 Software Discovery
- T1082 System Information Discovery
- T1105 Ingress Tool Transfer
- T1219 Remote Access Tools
- T1133 External Remote Services
- T1608 Stage Capabilities
- T1588 Obtain Capabilities

## Sources

- [A Fake Teams Update Can Give Hackers Two Separate Ways to Control Your PC](https://cybersecuritynews.com/fake-teams-update-gain-pc-control/)
- [Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update](https://thehackernews.com/2026/07/operation-bluedash-deploys-level-rmm.html)
- [berry4603/Bluedashltd (phishing infrastructure repository)](https://github.com/berry4603/Bluedashltd)
- [Signed malware impersonating workplace apps deploys RMM backdoors](https://www.microsoft.com/en-us/security/blog/2026/03/03/signed-malware-impersonating-workplace-apps-deploys-rmm-backdoors/)
- [How Threat Actors Abuse Remote Management Tools (daisy-chaining rogue RMM tools)](https://www.huntress.com/blog/daisy-chaining-rogue-rmm-tools)
- [Threat Actors Leverage Several RMM Tools in Phishing Attack to Maintain Remote Access](https://cybersecuritynews.com/threat-actors-leverage-several-rmm-tools/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1732
