Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fake Teams Update Grants Hackers Dual PC Control

Fake Teams Update Grants Hackers Dual PC Control

Posted on July 27, 2026 By CWS

Cybersecurity experts have identified a new phishing campaign, termed Operation BlueDash, which deceives users into downloading a counterfeit Microsoft Teams update. This malicious update grants attackers two separate methods to remotely control the compromised devices.

How the BlueDash Campaign Operates

The attack begins with an email falsely stating that a document was too large to send directly and has instead been shared through Microsoft Teams. When users click on the provided link, they are redirected through compromised sites to a fraudulent Microsoft Store page that mimics legitimate Teams branding, complete with screenshots and a spoofed Windows taskbar.

This strategy reflects an increasing trend in phishing attacks leveraging Teams-themed hooks. According to Google’s Mandiant team, similar campaigns, such as UNC6692, have impersonated IT support staff on Teams to distribute credential-stealing malware and backdoors.

Mechanism of the Fake Teams Update

Upon clicking “Update,” victims unknowingly download a file named supportdev.exe. This file, disguised as a Teams installer, is actually an Inno Setup package that silently runs a PowerShell script in the background. This script performs two tasks simultaneously: it installs the legitimate Level RMM remote-monitoring tool and attempts to set up ScreenConnect, a secondary remote-access client.

This dual approach makes the attack particularly resilient. By using legitimate, signed administrative software instead of custom malware, the activities blend seamlessly with normal IT operations, as highlighted in Microsoft’s March 2026 research on similar campaigns.

Detecting and Preventing Such Attacks

Once remote access is gained, attackers execute reconnaissance commands to assess system configurations, including checking for active BitLocker encryption and firewall settings. This hands-on phase provides a critical detection window, as the commands stem from unauthorized remote sessions.

Researchers traced the phishing kit’s source code to a public GitHub repository, revealing an extended history of infrastructure rotation and a concurrent Zoom-themed campaign using similar tactics.

Protective Measures Against Phishing Attacks

To safeguard against such threats, treat unsolicited emails regarding secure documents or software updates linked to Teams or Zoom as high-risk. Always verify updates through official sources and enable detection rules for hidden PowerShell windows.

Maintaining a whitelist of approved remote tools and enforcing multi-factor authentication can significantly enhance security. Monitoring unusual changes to the local administrator group is also crucial.

Remaining vigilant against “update now” prompts in emails is essential for defending against evolving phishing attacks.

Cyber Security News Tags:cyber threat, Cybersecurity, fake updates, Hacking, IT security, Malware, Microsoft Teams, Phishing, remote control, security measures, social engineering

Post navigation

Previous Post: NVIDIA Leads Formation of Open Secure AI Alliance
Next Post: Security Risk Advisors Earns CRN Channel Award Nomination

Related Posts

Microsoft Warns of Hackers Abuse Teams Features and Capabilities to Deliver Malware Microsoft Warns of Hackers Abuse Teams Features and Capabilities to Deliver Malware Cyber Security News
Threat Actors Weaponize PDF Editor With New Torjan to Turn Device Into Proxy Threat Actors Weaponize PDF Editor With New Torjan to Turn Device Into Proxy Cyber Security News
SimonMed Data Breach Exposes 1.2 Million Patients Sensitive Information SimonMed Data Breach Exposes 1.2 Million Patients Sensitive Information Cyber Security News
Reflectiz and Taboola Webinar on Third-Party Security Reflectiz and Taboola Webinar on Third-Party Security Cyber Security News
New “123 | Stealer” Advertised on Underground Hacking Forums for 0 Per Month New “123 | Stealer” Advertised on Underground Hacking Forums for $120 Per Month Cyber Security News
Top 10 Best Security Orchestration, Automation, And Response (SOAR) Tools in 2025 Top 10 Best Security Orchestration, Automation, And Response (SOAR) Tools in 2025 Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Security Risk Advisors Earns CRN Channel Award Nomination
  • Fake Teams Update Grants Hackers Dual PC Control
  • NVIDIA Leads Formation of Open Secure AI Alliance
  • Linux Servers Vulnerable After Microsoft Defender Update
  • GitHub Implements Cooldown to Thwart Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Security Risk Advisors Earns CRN Channel Award Nomination
  • Fake Teams Update Grants Hackers Dual PC Control
  • NVIDIA Leads Formation of Open Secure AI Alliance
  • Linux Servers Vulnerable After Microsoft Defender Update
  • GitHub Implements Cooldown to Thwart Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark