RMM (Remote Monitoring and Management) phishing attacks now start with something as ordinary as a Teams notification. That is exactly why they work. Researchers call the campaign Operation BlueDash. It tricks staff into installing genuine remote monitoring software. The trick is simple: dress it up as a routine Microsoft Teams update. Here is what is actually happening, and the checks that catch it before it costs you anything.

Table of Contents
What the scam looks like from the inside
An email arrives claiming a document was too large to send directly. It says the file was shared securely through Teams instead. The link leads to a fake Microsoft Store page. It is styled convincingly, with Teams branding and screenshots. It says the app needs updating before the file will open. Clicking through downloads a file named supportdev.exe.
That file is not obviously malicious. It is packaged with Inno Setup, a tool used by thousands of legitimate Windows installers. So it slips past casual inspection. Once run, it opens a hidden PowerShell window. That window quietly installs the genuine Level RMM tool. It enrols the machine into an environment the attackers control. As a second layer of access, it then installs ConnectWise ScreenConnect too. A parallel version of the same trick uses a fake Zoom update. That one pushes Tactical RMM instead.
Why RMM phishing attacks slip past antivirus
Level RMM and ScreenConnect are real products with valid signatures. Legitimate IT teams use them every day. Because the software itself is not malicious, many security tools do not flag the install. The danger comes entirely from who controls the enrolment, not from the code. That single fact is what makes this style of attack so persistent. Microsoft’s own researchers described a near-identical pattern in a separate campaign earlier this year. It impersonated Teams, Zoom, Adobe Reader and Google Meet. It also fits a wider pattern of phishing kits built to slip past standard defences, including the session-cookie theft used in the Kratos MFA bypass campaign we covered previously.
ZeroBEC attributes Operation BlueDash to a threat actor group operating from Nigeria, with moderate to high confidence. It bases that on infrastructure, code history and a public GitHub repository used to run the campaign. That repository shows the operation has been active since at least February 2026. This is not a one-off test run. It is an established, ongoing effort worth planning around, not just reacting to once.
Four checks worth doing this week
First, review which RMM or remote-access tools are approved for use in your organisation. Write that list down if it does not already exist. Anything outside it is worth investigating immediately.
Second, check your endpoint protection or asset inventory for RMM software your IT team did not install. Level RMM, ScreenConnect, Tactical RMM and MeshAgent are the names that keep turning up in these campaigns. Search for them specifically.
Third, look at who has downloaded and run executables from links inside Teams or email messages recently, not just attachments. The lure hides behind a “secure document” story. Staff often will not think to report it as suspicious.
Fourth, treat any unapproved RMM install the same way you would treat a confirmed backdoor. ZeroBEC’s researchers, who first identified Operation BlueDash, found the operators checking reboot status, BitLocker state, firewall rules and local Administrators group membership after gaining access. Assume they have already looked. Act accordingly, rather than simply uninstalling the software and moving on.
The bigger habit to build
Software update prompts are one of the most trusted moments in a user’s day. That is exactly why RMM phishing attacks keep aiming for them. Train staff to update software only through the application itself, or through IT-managed channels. This closes off the route more reliably than any single piece of technology, and it costs nothing. One short conversation is all it takes.
Walking staff through what the fake page actually looks like helps too, rather than describing it in the abstract. Operation BlueDash’s counterfeit Microsoft Store page includes Teams branding, screenshots and even a spoofed Windows taskbar. A five-minute screenshot walkthrough in a team meeting does more good than a generic warning about “suspicious links”. People spot fakes far more reliably once they have seen a real example of one.
Where a pen test earns its keep
If you commission a penetration test or a wider security review this year, ask explicitly whether the scope covers unauthorised RMM enrolment, not just malware and exploit paths. A tester who can install a legitimate, signed remote-access tool during an engagement, and go unnoticed, has found exactly the gap that RMM phishing attacks like Operation BlueDash exploit in the wild. That result is worth more than a clean scan. It tells you exactly what RMM phishing attacks like this one would actually get away with.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.