Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Phishing Attack Evades Detection Using Fake Teams Update

Phishing Attack Evades Detection Using Fake Teams Update

Posted on July 27, 2026 By CWS

Cybersecurity experts have uncovered a phishing campaign leveraging fake Microsoft Teams updates to install remote monitoring and management (RMM) tools. Dubbed Operation BlueDash, this attack aims to exploit unsuspecting users by mimicking legitimate software updates.

Phony Microsoft Store Page Delivers Malware

The attack initiates when victims are redirected to a counterfeit Microsoft Store webpage, purportedly requiring an update to Microsoft Teams for accessing a shared document. This bogus page, known as “teamvem[.]com,” facilitates the download of “supportdev.exe,” an executable that silently runs a PowerShell script. This script fetches and installs a legitimate Level RMM tool while establishing connections using a compromised enrollment key.

Additionally, the same script attempts to deploy ConnectWise ScreenConnect, suggesting a strategy to gain persistent remote access by using multiple tools. The usage of RMM tools in malicious campaigns is not unprecedented. Earlier, Microsoft flagged phishing operations that delivered malware like TrustConnect through similar tactics.

Operation BlueDash: Targets and Techniques

ZeroBEC, the cybersecurity firm tracking this operation, attributes it to a threat group based in Nigeria. The group employs a combination of compromised infrastructure, historical code analysis, and GitHub environments to execute its campaigns. The simultaneous deployment of numerous RMM tools aims to ensure continued access, even if one tool is detected and removed.

Once installed, the attackers probe the infected system by executing commands to assess reboot status, encryption measures, firewall configurations, and administrative group memberships. This reconnaissance aids in determining the most effective method for maintaining control over the targeted systems.

Expanding Threats and Defensive Measures

The infrastructure supporting these attacks includes domains like “support[.]berrydev[.]xyz” and GitHub repositories such as “Bluedashltd” and “rustovni.” These resources contain phishing materials, configuration files, and payload delivery mechanisms. Investigations reveal that this campaign has been active since early 2026, with a focus on exploiting popular workplace applications.

In parallel, ZeroBEC has reported on JIVS PhishKit, a tool for harvesting mailbox credentials across platforms like Microsoft 365 and Google Workspace. This kit uses generic phishing pages to capture email addresses and passwords, bypassing advanced security features like multi-factor authentication.

The rise of sophisticated phishing-as-a-service kits like Kratos, recently dismantled by international authorities, underscores the evolving threat landscape. These services enable widespread phishing operations, fueling an ongoing battle between cybercriminals and security professionals.

As cyber threats grow more complex, organizations must enhance their defenses by implementing robust security measures and educating employees on recognizing phishing attempts. Staying informed about these evolving tactics is crucial for safeguarding sensitive information and maintaining cyber resilience.

The Hacker News Tags:cyber threat, Cybersecurity, email security, fake updates, GitHub, hacker group, IT security, Malware, Microsoft Teams, Nigeria, Phishing, remote access, RMM tools, ZeroBEC

Post navigation

Previous Post: Claude Opus 5 Enhances Security with Controlled Exploit Generation
Next Post: Beelzebub Secures $3.4M to Enhance Cybersecurity Platform

Related Posts

Achieving IAM Compliance: Essential Guidelines Achieving IAM Compliance: Essential Guidelines The Hacker News
Cursor AI Code Editor Vulnerability Enables RCE via Malicious MCP File Swaps Post Approval Cursor AI Code Editor Vulnerability Enables RCE via Malicious MCP File Swaps Post Approval The Hacker News
Microsoft Sets Passkeys Default for New Accounts; 15 Billion Users Gain Passwordless Support Microsoft Sets Passkeys Default for New Accounts; 15 Billion Users Gain Passwordless Support The Hacker News
New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs The Hacker News
Microsoft Defender Zero-Day Exploits Unpatched Microsoft Defender Zero-Day Exploits Unpatched The Hacker News
Malicious PyPI Package soopsocks Infects 2,653 Systems Before Takedown Malicious PyPI Package soopsocks Infects 2,653 Systems Before Takedown The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic
  • China-Linked Hackers Exploit Sogou Flaw for Backdoor
  • Hackers Hide AI Threats in Plain English, Evade Security
  • Exploits Target JFrog Artifactory Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic
  • China-Linked Hackers Exploit Sogou Flaw for Backdoor
  • Hackers Hide AI Threats in Plain English, Evade Security
  • Exploits Target JFrog Artifactory Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark