Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
ShinyHunters Claims Data Theft From EY, Stealing Company Data
July 27, 2026
Critical vBulletin Bug CVE-2019-16759 Lets Attackers Remotely Execute Code
July 27, 2026
Fake Microsoft Teams Update Delivers Two Critical Malware Threats
July 27, 2026
Home/CyberSecurity News/Fake Microsoft Teams Update Delivers Two Critical Malware Threats
CyberSecurity News

Fake Microsoft Teams Update Delivers Two Critical Malware Threats

Key Takeaways A new phishing campaign, “Operation BlueDash,” is leveraging fake Microsoft Teams update notifications to trick users. Victims unknowingly install two legitimate remote...

Jennifer sherman
Jennifer sherman
July 27, 2026 3 Min Read
2 0

Key Takeaways

  • A new phishing campaign, “Operation BlueDash,” is leveraging fake Microsoft Teams update notifications to trick users.
  • Victims unknowingly install two legitimate remote monitoring and management (RMM) tools, Level RMM and ScreenConnect, giving attackers persistent control.
  • The attack begins with a phishing email claiming a large document was shared via Teams, leading to a convincing fake Microsoft Store page.
  • This sophisticated social engineering tactic uses legitimate software, making detection more challenging.

A sophisticated phishing campaign, dubbed “Operation BlueDash,” is actively deceiving users into installing a fraudulent Microsoft Teams update. This elaborate scheme grants attackers not one, but two distinct pathways to remotely control compromised computers, posing a significant security risk to organizations.

Table Of Content

  • Key Takeaways
  • Fake Teams Update to Gain PC Control
  • What You Should Do

The infection chain typically commences with an email informing recipients that a document was “too large” for direct transmission and was instead securely shared through Microsoft Teams. This initial lure sets the stage for the subsequent malicious activity.

According to the ZeroBEC Team, when unsuspecting victims click the embedded link in the phishing email, they are first redirected through a series of compromised websites. Ultimately, they land on a highly convincing fake Microsoft Store page. This fraudulent page is meticulously crafted with authentic-looking Teams branding, screenshots, and even a spoofed Windows taskbar, all designed to mimic a legitimate software update prompt and persuade users to proceed.

This method of leveraging Teams-themed social engineering mirrors a growing trend in cyberattacks. Google’s Mandiant team recently documented a related operation, UNC6692, where threat actors impersonated IT helpdesk personnel within Teams to deploy credential-stealing malware and backdoors. Similarly, other security researchers have uncovered instances of SEO-poisoned fake Teams installers distributing the Oyster backdoor onto corporate networks, highlighting the pervasive nature of these Teams-centric threats.

Fake Teams Update to Gain PC Control

Upon a victim clicking the “Update” button on the fake Microsoft Store page, a file named supportdev.exe is downloaded and executed. This file is not a genuine Teams installer; instead, it is an Inno Setup package designed to launch a hidden PowerShell window in the background. From this concealed process, the attack simultaneously performs two critical actions:

  • It downloads and installs the legitimate Level RMM remote-monitoring tool. Crucially, the device is enrolled into the attacker’s environment using a hardcoded API key, bypassing any need for user approval.
  • Concurrently, it attempts to install ScreenConnect, serving as a second, redundant remote-access client. This dual-channel strategy ensures attackers maintain control even if one access method is compromised or disabled.

This dual-channel approach significantly enhances the resilience of the attack. By utilizing legitimate, signed administrative software rather than custom malware, the malicious activity is able to blend in more effectively with normal IT operations. Microsoft itself noted this tactic in its March 2026 research, which detailed similar campaigns abusing ScreenConnect, Tactical RMM, and MeshAgent for illicit access.

Following the establishment of remote control, the attackers proceed to execute reconnaissance commands. These commands are used to gather intelligence on the compromised system, checking for conditions such as the need for a system reboot, the activation status of BitLocker disk encryption, the current firewall configuration, and the members of the local Administrators group.

This hands-on behavior indicates a deliberate assessment phase by the attackers, moving beyond mere automated malware deployment. Such actions present a crucial detection opportunity for defenders, as these commands originate from an unauthorized remote-access session rather than routine IT work, as reads the ZeroBEC Team report shared by CybersecurityNews.

Investigators further traced the phishing kit’s source code, custom domains, and commit history to a public GitHub repository. This forensic analysis revealed months of infrastructure rotation and uncovered a parallel Zoom-themed campaign employing similar tactics with Tactical RMM, indicating a broader, ongoing operation.

What You Should Do

  • Exercise extreme caution with unsolicited emails that claim to share “secure documents” or request software updates for applications like Teams or Zoom, especially if links direct to unfamiliar or compromised websites.
  • Always verify and obtain software updates exclusively from official application stores or directly from vendor websites, never through email links or third-party prompts.
  • Implement endpoint detection rules to identify and flag hidden PowerShell windows launched by installer executables, which can indicate malicious activity.
  • Maintain an allowlist of approved remote-monitoring tools within your organization and configure alerts for any unrecognized RMM agent installations.
  • Enforce multi-factor authentication (MFA) across all accounts and actively monitor for any unusual or unauthorized changes to local administrator groups.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCybersecurityMalwarephishingSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

GitHub adds 3-day Dependabot cooldown to block malicious package updates

Next Post

Critical vBulletin Bug CVE-2019-16759 Lets Attackers Remotely Execute Code

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
MedusaHVNC Malware Lets Attackers Remotely Control PCs
July 27, 2026
Vatican Click to Pray App API Flaw Exposes 700,000 User Records
July 27, 2026
Claude Opus 5 AI Identifies Software Vulnerabilities, Cannot Create Exploits
July 27, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us