As cited
Copy frozen at (site build).
threat intel
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
Researchers identified a phishing campaign using Microsoft Teams-themed lures to trick users into visiting a fake Microsoft Store page and downloading legitimate RMM tools. The attack chain redirects victims through compromised web infrastructure to deliver software like Level and ScreenConnect under the guise of a required Teams update.
Why it matters: Organizations relying on Teams are targeted by this campaign, and end users may install legitimate but attacker-controlled RMM tools that enable lateral movement and persistent access into corporate networks.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
Researchers identified a phishing campaign using Microsoft Teams-themed lures to trick users into visiting a fake Microsoft Store page and downloading legitimate RMM tools. The attack chain redirects victims through compromised web infrastructure to deliver software like Level and ScreenConnect under the guise of a required Teams update.
Why it matters: Organizations relying on Teams are targeted by this campaign, and end users may install legitimate but attacker-controlled RMM tools that enable lateral movement and persistent access into corporate networks.
- Source published
- First seen by Cybersecurity Tracker