Threat Advisory

Operation BlueDash Phishing Alert

Threat: Phishing Campaign
Threat Actor Name: Nigeria-based developer group
Targeted Region: Global
Threat Actor Region: Nigeria
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A threat actor, believed to be based in Nigeria, is behind a phishing operation that targets organizations through Microsoft Teams-themed emails. The goal of the attack is to gain remote access to the victim's endpoint, with the ultimate objective of data theft or disruption. The campaign primarily targets sectors that rely on Microsoft Teams for communication, with a focus on regions where the platform is widely used.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A threat actor, believed to be based in Nigeria, is behind a phishing operation that targets organizations through Microsoft Teams-themed emails. The goal of the attack is to gain remote access to the victim's endpoint, with the ultimate objective of data theft or disruption. The campaign primarily targets sectors that rely on Microsoft Teams for communication, with a focus on regions where the platform is widely used.[emaillocker id="1283"]

The malware infects systems through a phishing email that directs the victim to a counterfeit Microsoft Store page, where they are prompted to update Microsoft Teams. The update downloads a loader that launches a hidden PowerShell command, which retrieves the official Level RMM installer and enrolls the endpoint into the attacker's remote monitoring and management environment. The attacker also attempts to deploy ScreenConnect in parallel, providing a redundant remote-access channel. Once inside, the malware allows the attacker to maintain control and conduct reconnaissance on the compromised endpoint.

This threat is significant for organizations because it is difficult to detect and recover from, given the use of legitimate remote monitoring and management tools and the attacker's ability to conduct hands-on assessment of the compromised endpoint. To defend against this threat, organizations should take defensive actions such as patching, monitoring, backups, and endpoint protection. They should also be cautious when receiving emails with links to software updates and verify the authenticity of such requests to avoid falling victim to the phishing campaign.

THREAT PROFILE:

Tactic Technique ID Technique Sub-technique
Resource Development T1583.001 Acquire Infrastructure Domains
Initial Access T1566.001 Phishing Spearphishing Attachment
Execution T1059.001 Command and Scripting Interpreter PowerShell
Persistence T1543.003 Create or Modify System Process Windows Service
Discovery T1082 System Information Discovery
Discovery T1518.001 Software Discovery Security Software Discovery
Lateral Movement T1021.004 Remote Services SSH
Command and Control T1105 Ingress Tool Transfer

REFERENCES:

The reports contain further technical details:
https://zerobec.com/blog/operation-bluedash-multi-rmm-workplace-phishing
https://thehackernews.com/2026/07/operation-bluedash-deploys-level-rmm.html

[/emaillocker]
crossmenu