EXECUTIVE SUMMARY
A threat actor, believed to be based in Nigeria, is behind a phishing operation that targets organizations through Microsoft Teams-themed emails. The goal of the attack is to gain remote access to the victim's endpoint, with the ultimate objective of data theft or disruption. The campaign primarily targets sectors that rely on Microsoft Teams for communication, with a focus on regions where the platform is widely used.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A threat actor, believed to be based in Nigeria, is behind a phishing operation that targets organizations through Microsoft Teams-themed emails. The goal of the attack is to gain remote access to the victim's endpoint, with the ultimate objective of data theft or disruption. The campaign primarily targets sectors that rely on Microsoft Teams for communication, with a focus on regions where the platform is widely used.[emaillocker id="1283"]
The malware infects systems through a phishing email that directs the victim to a counterfeit Microsoft Store page, where they are prompted to update Microsoft Teams. The update downloads a loader that launches a hidden PowerShell command, which retrieves the official Level RMM installer and enrolls the endpoint into the attacker's remote monitoring and management environment. The attacker also attempts to deploy ScreenConnect in parallel, providing a redundant remote-access channel. Once inside, the malware allows the attacker to maintain control and conduct reconnaissance on the compromised endpoint.
This threat is significant for organizations because it is difficult to detect and recover from, given the use of legitimate remote monitoring and management tools and the attacker's ability to conduct hands-on assessment of the compromised endpoint. To defend against this threat, organizations should take defensive actions such as patching, monitoring, backups, and endpoint protection. They should also be cautious when receiving emails with links to software updates and verify the authenticity of such requests to avoid falling victim to the phishing campaign.
THREAT PROFILE:
| Tactic | Technique ID | Technique | Sub-technique |
| Resource Development | T1583.001 | Acquire Infrastructure | Domains |
| Initial Access | T1566.001 | Phishing | Spearphishing Attachment |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Persistence | T1543.003 | Create or Modify System Process | Windows Service |
| Discovery | T1082 | System Information Discovery | — |
| Discovery | T1518.001 | Software Discovery | Security Software Discovery |
| Lateral Movement | T1021.004 | Remote Services | SSH |
| Command and Control | T1105 | Ingress Tool Transfer | — |
REFERENCES:
The reports contain further technical details:
https://zerobec.com/blog/operation-bluedash-multi-rmm-workplace-phishing
https://thehackernews.com/2026/07/operation-bluedash-deploys-level-rmm.html