Microsoft Teams phishing campaign uses remote access tools to target victims

 

Microsoft Teams phishing campaign uses remote access tools to target victims

Cybersecurity researchers have discovered a phishing campaign that pretends to be a Microsoft Teams update to trick users into giving attackers remote access to their computers.

The attack starts with a fake ‘secure document’ link. Victims are sent to a fake Microsoft Store page that claims Teams must be updated before they can open the shared file. Instead of installing an update, the download launches a hidden PowerShell command that installs legitimate remote monitoring and management (RMM) software, including Level RMM and ConnectWise ScreenConnect.

Researchers say the attackers often install more than one RMM tool on the same device to have backup access if one program is detected and removed. After gaining access, the attackers check the system's security settings, firewall status, encryption, and administrator accounts before the next stage.

The campaign, named ‘Operation BlueDash,’ has been linked with moderate-to-high confidence to a Nigeria-based threat group. Researchers traced the operation, active since at least February 2026, through its online infrastructure, code history, and GitHub repositories.

Researchers also found a second phishing campaign using fake Zoom meeting invitations. Instead of Teams, it tricks users into installing Tactical RMM, another legitimate remote management tool.

“Operation BlueDash is not an isolated fake Teams page and not a single RMM installer. It is a continuously developed phishing and remote-access operation whose operators rotate workplace brands, compromised sites, custom domains, cloud-hosting services, payload formats, and RMM platforms while preserving the same objective: durable interactive control of victim endpoints,” the researchers noted in the report.

Back to the list