🟠 High | Source: The Hacker News
Operation BlueDash is a phishing campaign that impersonates Microsoft Teams update prompts, directing victims through compromised websites to fake Microsoft Store pages. Once deceived, victims install legitimate RMM tools — Level RMM and ScreenConnect — which attackers abuse to gain persistent, stealthy remote access. This matters because using trusted, signed software bypasses many endpoint security controls and leaves little suspicious artefact for defenders to detect.
Security Architect’s Take: Review and enforce application allowlisting policies to block unauthorised RMM tool installations, and ensure conditional access policies flag or block new RMM agent enrolments from unmanaged devices. Consider monitoring for unexpected outbound connections to Level RMM and ScreenConnect relay infrastructure as a detection signal.
Original advisory: Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update