BlueDash Delivers RMM Agents via Fake Teams Update
ZeroBEC researchers flagged Operation BlueDash, a phishing campaign delivering Level RMM and ScreenConnect via a counterfeit Microsoft Teams update page.
RMM agents are built to persist. That is the feature. Level RMM and ConnectWise ScreenConnect run as system-level services, reconnect automatically after reboots, and are designed to survive software updates without losing their session state. The enterprise trust model that makes them useful to IT is the same property that makes them useful to an attacker who can get one installed.
Operation BlueDash is doing exactly that. The delivery chain, documented by ZeroBEC on July 27, starts with a “secure document” lure that redirects the target through compromised web infrastructure to a counterfeit Microsoft Store page. The page asserts that Teams requires an update before the document can open. What installs is Level RMM and ScreenConnect — two legitimate remote management agents, both now running persistently and connected to infrastructure the attacker controls. No attribution has been published.
The detection gap is structural. Both products are on corporate allow-lists in most enterprise environments. Endpoint detection tools tuned for malware signatures will not flag them; neither will network monitoring that treats RMM traffic as routine management telemetry. What remains is behavioral: an RMM agent installed outside a recognized deployment pipeline, connecting to an endpoint management server that is not in the organization’s asset inventory.
That infrastructure layer — the one that has been accumulating RMM agents across devices for years without a complete audit — is where BlueDash lands and where it is hardest to see. Legacy remote access tools from previous IT vendors, acquired subsidiaries, or lapsed MSP contracts are still running in many environments. BlueDash does not need to find a vulnerability. It needs to look like one more entry in an already crowded field.
The social engineering dependency is also its clearest failure point: Teams does not update via the Microsoft Store in response to a document prompt. That is not how Teams updates work. A lure that claims otherwise is enough to flag if the user knows to question it. BlueNoroff’s Zoom phishing kit and the Steam forum ClickFix campaigns delivering XMRig are running variations on the same premise this week — trust in a familiar platform used to prompt installation of something that serves the attacker. Counterfeit Microsoft 365 pages via hotel Wi-Fi DNS hijacks are a parallel channel using the same counterfeit-Microsoft-property framing.
One concrete action: pull a list of every RMM agent running in your environment and check whether each was deployed through an authorized process. Anything that wasn’t is worth treating as an incident. The gap BlueDash is built to exploit is not new software — it is unaudited old software that has been running quietly long enough that nobody is watching it anymore.
Found this useful? Share it.


