A specialized social engineering campaign targeting corporate users has been uncovered, using fraudulent collaboration software landing pages to distribute legitimate remote monitoring and management tools. The operation lures users into installing secondary administrative agents that provide remote attackers with persistent interactive system access.
The campaign, designated as Operation BlueDash, redirects victims through compromised web infrastructure to a counterfeit Microsoft Store portal hosting fake Microsoft Teams update notifications. When an employee downloads the offered executable supportdev.exe, an Inno Setup installer executes a hidden PowerShell script. The script connects to official repositories to install Level RMM with a preconfigured attacker enrollment key, while simultaneously fetching and installing ConnectWise ScreenConnect in parallel to establish redundant remote persistence channels.
Deploying unauthorized remote monitoring tools onto enterprise workstations neutralizes network boundary controls. Because RMM software utilizes signed binaries and encrypted outbound connections over standard web ports, security monitoring systems frequently fail to flag the installer traffic, granting attackers persistent interactive access to capture credentials, execute background scripts, and pivot into corporate internal subnets.
– Implement domain filtering rules across secure web gateways to block connections to known malicious update domains like teamvem.com.
– Configure endpoint security policies to restrict unprivileged users from executing unverified RMM installation binaries.
– Audit host operational telemetry for unexpected background PowerShell processes carrying API key registration arguments.
– Maintain strict application whitelisting parameters to prevent unauthorized remote management agents from registering on endpoints.
Endpoint security management relies on continuous application inventory checks combined with strict download filtering to guarantee that external social engineering lures cannot deploy unauthorized administrative software. #CodeDefence #Microsoft #OperationBlueDash #Phishing #RMM #EndpointSecurity #ThreatIntel
/
