hacker-news · Crawled Jul 27, 2026

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

8 IoCs
Read original article ↗

AI Summary

Operation BlueDash is a phishing campaign leveraging fake Microsoft Teams and Zoom update lures to distribute legitimate remote monitoring and management (RMM) tools such as Level RMM and ScreenConnect. The attackers use counterfeit websites and malicious installers to establish persistent remote access on compromised systems. The campaign, attributed to a threat actor group based in Nigeria, employs redundant RMM deployments to ensure access resilience and conducts post-compromise reconnaissance to assess system state and privilege levels.

AI-extracted · verify before operational use

Indicators of Compromise 8 extracted

Type Value Detail
Domain teamvem[.]com Details →
Domain support[.]berrydev[.]xyz Details →
Domain berry4603[.]github[.]io Details →
Domain corychase[.]org Details →
Filename supportdev.exe Details →
GitHub Repo Bluedashltd Details →
GitHub Repo rustovni Details →
GitHub User berry4603 Details →