Fake Microsoft Teams Update Is Dropping Real RMM Tools on SMBs

What happened
Researchers this week disclosed a phishing operation, tracked as "Operation BlueDash," that uses a Microsoft Teams "secure document" lure to trick employees into installing legitimate remote monitoring and management (RMM) software — specifically Level RMM and ScreenConnect — on their workstations. According to reporting from feeds.feedburner.com / The Hacker News, victims are steered through compromised web infrastructure to a counterfeit Microsoft Store page that claims Teams must be updated before the shared document will open.
Once the "update" runs, the attacker has a signed, trusted remote-control tool sitting on the endpoint — no malware signature to trip, no obvious red flag in the Task Manager. From there, the operators can pivot, harvest credentials, stage ransomware, or quietly sell the access on. Attribution and full victim scope are still being verified by the original researchers, so treat specific IOCs as preliminary until your security vendor confirms them.

Why this matters for Pittsburgh SMBs
This campaign is aimed almost exactly at the profile of businesses we serve across Western PA: 10–200 employees, heavy Microsoft 365 users, and staff who are conditioned to click "Update Teams" without a second thought. If you're a CPA firm in tax season, a law office swapping documents with co-counsel, or a healthcare practice moving referrals around, a "secure document" lure is plausible — that's what makes it dangerous.
Two specific concerns for our client base:
- Compliance blast radius. If an attacker uses RMM to touch ePHI, CUI, or client financial records, you're not just cleaning up an incident — you're potentially triggering HIPAA breach notification, FTC Safeguards reporting, or a CMMC Level 2 nonconformity for defense contractors. Legitimate RMM tools also make it harder to prove "no data was accessed" after the fact.
- RMM-on-RMM confusion. Most managed IT stacks already run one sanctioned RMM agent. A second, unsanctioned one (Level, ScreenConnect, or otherwise) can hide in plain sight unless someone is actively baselining what should be installed. This is the exact scenario an EDR/MDR tuning conversation is built to catch.
Manufacturers and defense subs should pay extra attention: DFARS 7012 incident reporting clocks start ticking fast, and "we didn't notice the second remote-control tool for three weeks" is not a story you want to tell your prime.
What to do about it this week
You don't need a new product to blunt this campaign. You need five to seven boring things done well:
- Block unsanctioned RMM at the perimeter and the endpoint. Have your IT team add Level, ScreenConnect, AnyDesk, TeamViewer, Atera, and Splashtop to an application-control blocklist unless your business explicitly uses them. If you do use one, allowlist only that vendor's specific binaries and domains.
- Verify how Teams actually updates in your tenant. Microsoft Teams updates through the client itself or via Intune/Autopilot, never through a "Microsoft Store" web page prompt after opening a document. Send a one-paragraph note to staff this week making that explicit.
- Tune EDR alerts for "new remote-access tool installed." Ask your provider to confirm your endpoint tooling will fire on first-run of common RMM installers, not just on known malware hashes. If you don't have 24/7 MDR coverage, this is the week to price it.
- Audit installed software across the fleet. A simple report of every executable installed in the last 30 days, sorted by rarity, will surface a rogue RMM faster than any signature. This should be a standing monthly deliverable from your managed IT partner.
- Force MFA re-enrollment on anyone who reports a suspicious Teams prompt. Assume session tokens were stolen. Revoke sessions in Entra ID and rotate credentials — don't just "change the password."
- Run a 15-minute tabletop. Walk your leadership through: "An employee installed a fake Teams update at 2pm Friday. Who do we call, in what order, and what do we tell clients?" If the answer isn't crisp, that's the finding.
- Recheck your written IR and notification playbooks against your obligations. HIPAA, SOC 2, and FTC Safeguards all have different clocks. A quick pass with your compliance lead or vCIO is cheaper than getting it wrong under pressure.
A note on AI-assisted phishing: the lure quality in these campaigns keeps climbing, and user training alone will not save you. Layered controls — conditional access, application allowlisting, EDR, and a written acceptable-use policy that covers "what to do when a document asks you to install something" — are what actually hold.

How PGH Networks helps
We already run application control, EDR/MDR, and Microsoft 365 hardening for professional services, healthcare, manufacturing, and defense-contractor clients across the Pittsburgh region. If you're not sure whether an unsanctioned RMM could quietly install on one of your endpoints today — or whether your Microsoft 365 tenant would even log it — we can answer that in a short assessment. Our vCIO team can also line up the compliance-facing pieces (HIPAA, SOC 2, CMMC, FTC Safeguards) so a Friday-afternoon phishing click doesn't become a Monday-morning notification event.
Talk to us
Call 724.888.7007 or reach us through the contact form and we'll get a security engineer on the line the same business day.
Related reading

Custom GPT for Law Firm: Pittsburgh Build & Deploy
A custom GPT for law firm teams in Pittsburgh, built on your matter files, precedents, and templates, with the confidentiality controls your ethics rules require.

Business WiFi Setup in Pittsburgh: A 5-Step Process
Business WiFi setup in Pittsburgh done right: site survey, secure design, install, tuning, and ongoing management from a local MSP within 75 miles of 15220.

Business WiFi Installation in Pittsburgh: A Case Study
See how a Pittsburgh manufacturer fixed dead zones, roaming drops, and guest network risk with a properly designed business WiFi installation.