Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Phishing Attack Evades Detection Using Fake Teams Update

Phishing Attack Evades Detection Using Fake Teams Update

Posted on July 27, 2026 By CWS

Cybersecurity experts have uncovered a phishing campaign leveraging fake Microsoft Teams updates to install remote monitoring and management (RMM) tools. Dubbed Operation BlueDash, this attack aims to exploit unsuspecting users by mimicking legitimate software updates.

Phony Microsoft Store Page Delivers Malware

The attack initiates when victims are redirected to a counterfeit Microsoft Store webpage, purportedly requiring an update to Microsoft Teams for accessing a shared document. This bogus page, known as “teamvem[.]com,” facilitates the download of “supportdev.exe,” an executable that silently runs a PowerShell script. This script fetches and installs a legitimate Level RMM tool while establishing connections using a compromised enrollment key.

Additionally, the same script attempts to deploy ConnectWise ScreenConnect, suggesting a strategy to gain persistent remote access by using multiple tools. The usage of RMM tools in malicious campaigns is not unprecedented. Earlier, Microsoft flagged phishing operations that delivered malware like TrustConnect through similar tactics.

Operation BlueDash: Targets and Techniques

ZeroBEC, the cybersecurity firm tracking this operation, attributes it to a threat group based in Nigeria. The group employs a combination of compromised infrastructure, historical code analysis, and GitHub environments to execute its campaigns. The simultaneous deployment of numerous RMM tools aims to ensure continued access, even if one tool is detected and removed.

Once installed, the attackers probe the infected system by executing commands to assess reboot status, encryption measures, firewall configurations, and administrative group memberships. This reconnaissance aids in determining the most effective method for maintaining control over the targeted systems.

Expanding Threats and Defensive Measures

The infrastructure supporting these attacks includes domains like “support[.]berrydev[.]xyz” and GitHub repositories such as “Bluedashltd” and “rustovni.” These resources contain phishing materials, configuration files, and payload delivery mechanisms. Investigations reveal that this campaign has been active since early 2026, with a focus on exploiting popular workplace applications.

In parallel, ZeroBEC has reported on JIVS PhishKit, a tool for harvesting mailbox credentials across platforms like Microsoft 365 and Google Workspace. This kit uses generic phishing pages to capture email addresses and passwords, bypassing advanced security features like multi-factor authentication.

The rise of sophisticated phishing-as-a-service kits like Kratos, recently dismantled by international authorities, underscores the evolving threat landscape. These services enable widespread phishing operations, fueling an ongoing battle between cybercriminals and security professionals.

As cyber threats grow more complex, organizations must enhance their defenses by implementing robust security measures and educating employees on recognizing phishing attempts. Staying informed about these evolving tactics is crucial for safeguarding sensitive information and maintaining cyber resilience.

The Hacker News Tags:cyber threat, Cybersecurity, email security, fake updates, GitHub, hacker group, IT security, Malware, Microsoft Teams, Nigeria, Phishing, remote access, RMM tools, ZeroBEC

Post navigation

Previous Post: Claude Opus 5 Enhances Security with Controlled Exploit Generation
Next Post: Beelzebub Secures $3.4M to Enhance Cybersecurity Platform

Related Posts

Chinese Group Silver Fox Uses Fake Websites to Deliver Sainbox RAT and Hidden Rootkit Chinese Group Silver Fox Uses Fake Websites to Deliver Sainbox RAT and Hidden Rootkit The Hacker News
VerdantBamboo Targets Linux with New BRICKSTORM Variant VerdantBamboo Targets Linux with New BRICKSTORM Variant The Hacker News
RabbitMQ Vulnerabilities Expose OAuth Secrets, Threaten Security RabbitMQ Vulnerabilities Expose OAuth Secrets, Threaten Security The Hacker News
AI Scam Targets Google Discover with Fake News AI Scam Targets Google Discover with Fake News The Hacker News
North Korean Hackers Exploit AI for Enhanced Cyber Attacks North Korean Hackers Exploit AI for Enhanced Cyber Attacks The Hacker News
Microsoft Office Zero-Day (CVE-2026-21509) – Emergency Patch Issued for Active Exploitation Microsoft Office Zero-Day (CVE-2026-21509) – Emergency Patch Issued for Active Exploitation The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw in vBulletin Allows Remote Code Execution
  • Beelzebub Secures $3.4M to Enhance Cybersecurity Platform
  • Phishing Attack Evades Detection Using Fake Teams Update
  • Claude Opus 5 Enhances Security with Controlled Exploit Generation
  • MedusaHVNC Malware Uses Hidden Desktops for Stealth

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw in vBulletin Allows Remote Code Execution
  • Beelzebub Secures $3.4M to Enhance Cybersecurity Platform
  • Phishing Attack Evades Detection Using Fake Teams Update
  • Claude Opus 5 Enhances Security with Controlled Exploit Generation
  • MedusaHVNC Malware Uses Hidden Desktops for Stealth

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark