discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs 'secure document' lures to deliver legitimate remote monitoring and management (RMM) tools. The campaign, codenamed Operation BlueDash, has been active since at least February 2…

By Ravie Lakshmanan·Jul 27·thehackernews.com·3 min read

Intelligence analysis by Llama

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
Image: thehackernews.com

A Microsoft Teams-themed phishing campaign has been flagged, employing 'secure document' lures to deliver legitimate RMM tools. The campaign, codenamed Operation BlueDash, has been active since at least February 2026. The threat actors have been observed attempting to explore the infected host, running commands to determine system state, understand encryption and firewall posture, and…

Why it matters

This story matters to someone following Security because it highlights a new phishing campaign that employs 'secure document' lures to deliver legitimate RMM tools. The campaign, codenamed Operation BlueDash, has been active since at least February 2026.

Imagine you receive an email that looks like it's from Microsoft Teams, asking you to update your software before you can open a shared document. But it's actually a trick to get you to download a fake update that can harm your computer. This is called a phishing attack, and it's like a fake email that tries to trick you into doing something bad.

Analysis

A $60B Vote of Confidence

The latest set of phishing attacks has been codenamed Operation BlueDash, with the email security company attributing it with moderate-to-high confidence to a threat actor group operating from Nigeria based on an analysis of infrastructure, code history, and a GitHub environment used to operate the campaigns. The deployment of multiple RMM tools on the same host is seen as an attempt to set up redundant access and improve resilience in the event one of the programs is detected and removed from the environment.

Subsequently, the threat actors have been observed attempting to explore the infected host, running commands to determine if it's pending a reboot or whether the system volume was protected, measure active firewall profiles, enumerate members of the local Administrators group, and identify the local Administrators group name. This sequence suggests a practical operator checklist: determine system state, understand encryption and firewall posture, and identify privileged local users before deciding how to continue.

Further analysis of the threat actor infrastructure has uncovered a GitHub Pages domain and a repository named 'Bluedashltd' that contains the phishing source, CNAME configuration, and SupportDev payload. The commit history indicates that the campaign has been active since at least February 2026, when the repository was created with the fake Microsoft Store page featuring an 'update' for Teams.

What's more, a second repository tied to the same GitHub account has been found to host a Zoom meeting lure along with its payload-delivery components. The end goal, in this case, is to download the Tactical RMM agent from its official GitHub release, install it in the Windows temporary directory, and register the compromised host with the attacker using an embedded authentication token.

The disclosure comes as ZeroBEC detailed JIVS PhishKit, a coordinated mailbox credential-harvesting campaign targeting multiple users within the same organization to deliver a provider-agnostic phishing page that can target Microsoft 365, Google Workspace, cPanel, Roundcube, Zimbra, and other email identities. The earliest artifact related to the effort dates back to August 21, 2025.

The messages used an authenticated but unrelated external sender, warned that each recipient mailbox had violated policy, and directed users to a live PHP phishing page on corychase.org. The landing page was not a Microsoft clone. It presented a generic 'Session Expired' form that could be used against Microsoft 365, Google Workspace, hosted webmail, or almost any corporate identity.

The kit is designed to siphon a corporate email address and the password entered for that mailbox. No session cookies, OAuth tokens, multi-factor authentication (MFA) codes, or browser sessions are exfiltrated.

Key points

  • A Microsoft Teams-themed phishing campaign has been flagged, employing 'secure document' lures to deliver legitimate RMM tools.
  • The campaign, codenamed Operation BlueDash, has been active since at least February 2026.
  • The threat actors have been observed attempting to explore the infected host, running commands to determine system state, understand encryption and firewall posture, and identify privileged local users.
  • Further analysis of the threat actor infrastructure has uncovered a GitHub Pages domain and a repository named 'Bluedashltd' that contains the phishing source, CNAME configuration, and SupportDev payload.
  • The disclosure comes as ZeroBEC detailed JIVS PhishKit, a coordinated mailbox credential-harvesting campaign targeting multiple users within the same organization to deliver a provider-agnostic phishing page that can target Microsoft 365, Google Workspace, cPanel, Roundcube, Z…
The Upside

If this development plays out positively, it could lead to improved security measures being implemented by Microsoft and other companies to prevent such phishing attacks. This could include better authentication processes, more secure software updates, and increased awareness among users about the dangers of phishing.

The Downside

The realistic downside risks or failure modes of this development include the potential for more sophisticated phishing attacks to be launched, using new tactics and techniques to evade detection. This could lead to a greater number of users being tricked into downloading malware, and potentially even more severe consequences, such as data breaches or identity theft.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagscybersecurityphishingrmmmicrosoftteamsoperation bluedash

Author

Ravie Lakshmanan

Intelligence analysis by

Llama

Published

Jul 27, 2026

Source

thehackernews.com

Share

Topics

cybersecurityphishingrmmmicrosoftteamsoperation bluedash

Related

More from this desk

Jul 27·bleepingcomputer.com

Shadow AI Agents Are Multiplying. Here's How to Find and Secure Them.

Shadow AI agents are multiplying across various platforms, posing a significant risk to organizations. Nudge Security provides a solution to discover and secure these agents, ensuring visibility and control while enabling the workforce to experiment and automate.

Jul 27·thehackernews.com

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform.

Jul 27·thehackernews.com

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

Zscaler ThreatLabz has detailed a multi-stage cyber campaign by an East Asia-linked threat actor targeting Middle East governments using three new malware families: TELESHIM, MIXEDKEY, and BINDCLOAK.

Jul 27·thehackernews.com

GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption

GitHub has introduced a 3-day cooldown mechanism in Dependabot to limit the adoption of poisoned packages. This feature will help prevent attackers from pushing malicious versions of popular packages, which can then be quickly pulled by downstream projects.