Fake Microsoft Teams Update Pushes Remote-Control Tools onto Victims' PCs

A phishing run tracked as Operation BlueDash uses a bogus 'secure document' lure and a counterfeit Microsoft Store page to install legitimate remote-access software on target machines.

ThreatVectr Newsdesk· 4 min read
16:9 editorial photograph, full-frame edge-to-edge, of a hotel front-desk computer monitor glowing in a dimly lit reception area at night, the screen displaying
Share

Key points

  • Researchers at ZeroBEC have documented a phishing campaign, dubbed Operation BlueDash, that uses fake Microsoft Teams update prompts to trick staff into installing remote-control software.
  • Victims are steered through hacked websites to a counterfeit Microsoft Store page before the malicious installer runs.
  • The attackers deploy Level RMM and ConnectWise ScreenConnect, both legitimate remote monitoring and management tools that let outsiders drive a PC as if sitting at the keyboard.
  • The lure text pretends a shared document cannot open until Teams is updated, exploiting normal office habits.
  • Because the tools are signed and legitimate, many antivirus products do not flag them, giving the intruders a quiet foothold.

A new phishing campaign is tricking office workers into handing attackers full remote control of their computers, and it does so without a single line of custom malware.

The operation, named Operation BlueDash by researchers at ZeroBEC, dresses itself up as a Microsoft Teams notification about a shared document. Click the link, and you land on a hacked website that quietly bounces you to a fake Microsoft Store page. That page tells you Teams needs an update before the document will open.

It is a tidy trap. The story matches what people see every day at work.

What actually gets installed?

Not malware in the traditional sense. The installer drops one of two commercial remote monitoring and management tools, meaning software that IT teams normally use to fix laptops from afar: Level RMM or ConnectWise ScreenConnect. Once running, these give the attacker the same view and control a helpdesk technician would have.

That is the clever bit, and the nasty bit. The files are signed by real vendors. Antivirus tools tend to leave them alone, because thousands of legitimate businesses use them. As first reported by The Hacker News, the campaign relies entirely on this blurred line between IT tool and hacking tool.

How does the lure work in practice?

The victim clicks a link that appears to be a Teams message about a secure document. The link points to a website the attackers have already broken into, which forwards the browser to a page mocked up to look like the Microsoft Store. On that page, a prompt insists Teams must be updated. Agreeing to the update downloads the remote-access installer.

From there, the attacker can read files, watch the screen, harvest saved passwords from the browser, and move deeper into the corporate network.

Who is being targeted?

ZeroBEC has not named specific victims, but the lure design points squarely at businesses that live inside Microsoft 365. Anyone whose day involves Teams messages and shared files is a plausible target: finance, HR, legal, sales.

Detail What ZeroBEC reports
Campaign name Operation BlueDash
Lure theme Microsoft Teams shared document, fake update prompt
Delivery path Compromised websites redirecting to a fake Microsoft Store page
Payloads Level RMM, ConnectWise ScreenConnect
Detection risk Low, because both tools are legitimate and code-signed

What should staff and IT teams do?

A few practical steps go a long way.

For everyday users: Teams updates itself. If a web page tells you to update Teams to open a document, close the tab. Do not run installers that arrive through a browser prompt, no matter how official the page looks.

For IT and security teams: treat unexpected installs of RMM software as a red flag, even when the vendor is reputable. Block RMM binaries you do not use, and alert on the ones you do. Review outbound connections to Level and ScreenConnect cloud endpoints. If staff report a strange Teams update prompt, pull the machine off the network and check for unfamiliar remote-access services.

Regulatory exposure will depend on what the attackers reached. Firms in the UK that suffer a personal data breach through this route have 72 hours to notify the Information Commissioner's Office. In the US, sector rules from the SEC and state attorneys general may apply once material impact is confirmed.

© 2026 Threat Vectr