The record
Written from the 1 report below. Nothing here is unsourced.
- Cybersecurity researchers have identified a phishing campaign, Operation BlueDash, that uses fake Microsoft Teams and Zoom update pages to trick victims into installing legitimate remote monitoring and management (RMM) tools like Level RMM, ScreenConnect, and Tactical RMM.
- Once installed, these tools give attackers persistent remote access, and deploying multiple RMM programs provides redundancy if one is detected and removed.
- Researchers attribute the campaign with moderate-to-high confidence to a threat actor group operating from Nigeria, with activity dating back to at least February 2026.
- The disclosure comes alongside a separate credential-harvesting effort called JIVS PhishKit and follows the recent takedown of the Kratos phishing-as-a-service kit by authorities.
What to watch next
- Whether defenders publish detection guidance for unauthorized RMM enrollment activity
- Further takedowns or identification of the Nigeria-based threat actor behind Operation BlueDash
- Expansion of the multi-brand lure scheme to additional workplace applications
Coverage1
1 report
English national1
All filed from India
Named Nigeria · ConnectWise ScreenConnect · JIVS PhishKit · Kratos · Level RMM · MeshAgent · Microsoft · Sneaky 2FA · Tactical RMM · TrustConnect · ZeroBEC
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
