Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

The Rise of Operation BlueDash: A Phishing Campaign Leveraging RMM Tools to Establish Persistent Remote Access


Operation BlueDash: A phishing campaign leveraging RMM tools to deliver legitimate-looking phishing campaigns and establish persistent remote access. The operation's TTPs are similar to those seen in earlier campaigns, but with some notable differences.

  • Operation BlueDash is a sophisticated phishing campaign using RMM tools to deliver legitimate-looking phishing campaigns and establish persistent remote access.
  • The operation's tactics, techniques, and procedures (TTPs) are similar to those seen in earlier campaigns, but with some notable differences.
  • The threat actor group behind Operation BlueDash appears to be affiliated with another notorious phishing-as-a-service (PhaaS) kit known as Kratos.
  • The operation uses a provider-agnostic phishing page designed to target various email identities and has been linked to multiple phishing campaigns, including JIVS PhishKit.
  • The use of RMM tools in Operation BlueDash allows threat actors to establish persistent remote access, making it essential for organizations to implement robust security measures to prevent such attacks.



  • The cybersecurity landscape has witnessed a surge in sophisticated phishing campaigns, and Operation BlueDash is the latest to emerge as a threat actor group leveraging remote monitoring and management (RMM) tools to deliver legitimate-looking phishing campaigns. This report provides an in-depth analysis of the operation, its tactics, techniques, and procedures (TTPs), and the potential risks it poses to organizations.

    In recent weeks, ZeroBEC, a cybersecurity research firm, has been tracking Operation BlueDash, a Microsoft Teams-themed phishing campaign that uses "secure document" lures to deliver legitimate RMM tools. The operation appears to be attributed to a threat actor group operating from Nigeria, based on an analysis of infrastructure, code history, and a GitHub environment used to operate the campaigns.

    The phishing campaign in question is believed to have been launched since at least February 2026, when a fake Microsoft Store page featuring an "update" for Teams was created with the repository name "Bluedashltd." This initial phishing attempt uses the "teamvem[.]com" domain, which is used to deliver supportdev.exe, an Inno Setup-based loader that launches PowerShell in a hidden window.

    The PowerShell command fetches an official Level RMM installer and registers the endpoint using an attacker-controlled enrollment secret ("LEVEL_API_KEY=GxSCHE8EZwfyYN3iPQHPai8D"). The same PowerShell command has been found to download and deploy ConnectWise ScreenConnect in parallel, indicating an attempt to drop multiple RMM tools with the intent of establishing persistent remote access.

    It is essential to note that this phishing campaign follows a similar pattern seen in earlier campaigns, where threat actors have abused RMM tools to their advantage. Microsoft warned of multiple phishing campaigns earlier this year, using workplace meeting lures and PDF attachments to distribute signed malware dubbed TrustConnect, which then acted as a conduit for ScreenConnect.

    The current Operation BlueDash campaign appears to be part of a multi-brand scheme that keeps the core intact while altering the workplace application lure, payload host, and the remote management platform. Furthermore, this operation has also been linked to another phishing email campaign targeting multiple users within an organization, using a provider-agnostic phishing page designed to target Microsoft 365, Google Workspace, cPanel, Roundcube, Zimbra, and other email identities.

    The phishing page in question was found to be hosted on a domain controlled by the threat actor group ("rustovni"), which also hosts a second repository containing a Zoom meeting lure along with its payload-delivery components. The end goal of this operation is to download the Tactical RMM agent from its official GitHub release, install it in the Windows temporary directory, and register the compromised host with the attacker using an embedded authentication token.

    In addition to Operation BlueDash, ZeroBEC has also disclosed a second phishing campaign known as JIVS PhishKit, which targets multiple users within an organization to deliver a provider-agnostic phishing page designed to target various email identities. The earliest artifact related to this effort dates back to August 21, 2025.

    It is worth noting that the threat actor group responsible for Operation BlueDash appears to be affiliated with another notorious phishing-as-a-service (PhaaS) kit known as Kratos. German authorities, in collaboration with the U.S. and Indonesia, took down the Kratos PhaaS kit and arrested its alleged developer and technical administrator.

    The operation also follows a broader trend of threat actors weaponizing GitHub Actions Runners to target cPanel and WHM servers. Furthermore, Claude Cowork Flaw could let AI agents escape their VMs and access Mac files, while Kimi K3 Agents found Redis Zero-Days and built RCE exploit, researchers say.

    In conclusion, Operation BlueDash is a sophisticated phishing campaign that leverages RMM tools to establish persistent remote access. The operation's TTPs are similar to those seen in earlier campaigns, but with some notable differences. It is essential for organizations to remain vigilant and implement robust security measures to prevent such attacks.

    Operation BlueDash: A phishing campaign leveraging RMM tools to deliver legitimate-looking phishing campaigns and establish persistent remote access. The operation's TTPs are similar to those seen in earlier campaigns, but with some notable differences.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/The-Rise-of-Operation-BlueDash-A-Phishing-Campaign-Leveraging-RMM-Tools-to-Establish-Persistent-Remote-Access-ehn.shtml

  • https://thehackernews.com/2026/07/operation-bluedash-deploys-level-rmm.html


  • Published: Mon Jul 27 09:38:31 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us