Researchers tracking a campaign now called Operation BlueDash have documented a phishing operation that skips the part most email defenses are built to catch. There is no lookalike domain to flag, no spoofed sender to block, no failed authentication check to review. The email just tells the recipient that a document was too large to send directly and was shared securely through Microsoft Teams instead. Clicking the link is where the actual attack starts, and by the time it ends, the victim’s machine is enrolled in not one but three different commercial remote monitoring and management platforms, all installed by the victim’s own hand.
The Lure Is the Message, Not the Domain
The pretext is almost aggressively plain. An email arrives claiming a file was too big to attach and has been shared through Teams for convenience. Clicking through routes the victim across compromised web infrastructure to a counterfeit Microsoft Store page insisting a Teams update is required before the document can be opened. That single fake update page is doing all the work the rest of the campaign depends on. There is no attachment to scan, no malicious macro, no obviously wrong sending domain. The email’s job is only to get a click, and a plausible workplace excuse for a shared file is enough.
Three RMM Platforms Behind One Fake Update
What the counterfeit update actually installs is where Operation BlueDash stands out. Researchers found the campaign silently enrolling victim endpoints into Level RMM, ScreenConnect, and Tactical RMM, three separate legitimate remote monitoring and management tools that give an attacker full remote control once installed. Level RMM is a new addition to the toolset researchers have tracked from earlier campaigns using this same playbook, and running multiple RMM agents side by side gives the operator redundant access: if a victim or their IT team removes one, the others quietly remain.
The infrastructure behind the lure rotates deliberately across Netlify, GitHub Pages, and Dropbox, spreading the fake update pages and payload delivery across services that are themselves trusted and rarely blocked outright. Investigators traced the phishing kit’s source code, custom domains, and commit history back to a public GitHub repository created in February 2026, exposing months of the operators’ development activity. A second repository tied to the same account hosts a parallel campaign using a Zoom meeting lure instead of Teams, delivering Tactical RMM through the same basic structure. The threat actor behind both has been attributed with moderate to high confidence to a group operating out of Nigeria.
Why This Skips Past DMARC Entirely
DMARC verifies that a message’s From domain is authorized to send on behalf of the domain it claims. Operation BlueDash’s email does not need to claim to be from Microsoft, Teams, or anything the recipient’s mail server would check against a DNS record. It only needs to reference Teams as a delivery mechanism, a claim DMARC has no mechanism to evaluate because it is text in a message body, not a header. The actual impersonation, the fake Microsoft Store branding and the fraudulent update prompt, happens entirely on the web, a layer DMARC was never built to touch.
Even a domain with a perfect DMARC record enforced at p=reject would authenticate this email without objection, because the email itself is not spoofing that domain’s identity. And once Level RMM, ScreenConnect, or Tactical RMM is running, there is nothing left to authenticate. These are legitimate, digitally signed products used every day by managed service providers. Endpoint security tools built to flag unsigned malware have little reason to react, because from the operating system’s perspective, the victim installed a real, working piece of remote access software. That is the entire point of choosing commercial RMM tools over custom malware: the software is not the anomaly. The install decision is.
What Defenders Should Do Now
Treat “document too large, sent via Teams” as a scripted pretext, not a routine notification. Legitimate Teams file shares generate their own native notifications inside Teams itself; an email claiming this outside that flow is worth a second look regardless of how clean the message looks.
Inventory and restrict which RMM tools are authorized to run in your environment. Application allowlisting that blocks unapproved remote access software, even signed, reputable products like Level RMM, ScreenConnect, or Tactical RMM, closes the exact gap this campaign depends on.
Alert on new RMM agent installations outside your change management process. A second or third remote access tool appearing on an endpoint that already has one from your own IT stack is one of the clearest signals available that something outside your process installed it.
Keep your own domains at DMARC enforcement regardless. It will not stop a lure like this one, but it still closes the more common path where an attacker sends mail claiming to be your organization directly, freeing your team’s attention for threats like BlueDash that operate entirely outside DMARC’s authority.
The Takeaway
Operation BlueDash succeeds by being unremarkable at exactly the layer email security tools inspect. No spoofed domain, no failed authentication, no flagged attachment, just a plausible excuse and three real, signed pieces of software doing precisely what they were built to do. DMARC keeps your own name from being used against you directly, which is worth having regardless. It was just never the layer built to stop a fake software update page from talking a user into installing their own remote access backdoor.
Excello Mail keeps every domain you own fully authenticated and enforced, closing off the direct spoofing paths so your security team’s attention goes where campaigns like Operation BlueDash actually live, in the web infrastructure and software installs DMARC was never built to see. Sign up for free to Excello Mail to see your domain’s real authentication posture today.