Operation BlueDash Uses Multi-RMM Phishing for Access
Summary
Operation BlueDash is a sophisticated phishing campaign targeting workplace users with fake Microsoft Teams and Zoom update notifications. Attackers use counterfeit Microsoft Store pages to distribute loaders that silently enroll compromised endpoints into several Remote Monitoring and Management (RMM) platforms, including Level RMM, ScreenConnect, and Tactical RMM. This multi-channel setup gives the adversary redundant and resilient remote access to infected systems.
Investigation
The ZeroBEC investigation reconstructed the complete attack chain, from the initial phishing email through post-compromise reconnaissance. Researchers uncovered a public GitHub development environment containing phishing source code, custom domain configurations, and multiple loaders. Analysis of repository commit history showed how the campaign evolved from basic ScreenConnect delivery into a more advanced multi-RMM framework alongside a parallel Zoom-themed operation.
Mitigation
Organizations should enforce strong email and web controls to detect unsolicited document or software update lures. Technical defenses should include blocking unauthorized RMM tools through application control policies such as AppLocker or WDAC and monitoring for suspicious PowerShell activity. Maintaining an explicit allowlist of approved RMM products and their authorized enrollment keys is also strongly recommended.
Response
If unauthorized RMM enrollment is detected, security teams should immediately isolate the affected endpoint to limit further lateral movement. Every established remote-access channel should be removed, and all potentially compromised credentials should be rotated. After containment, responders should review RMM console activity and endpoint logs to determine the full scope of the compromise.