Cybersecurity researchers have identified an Operation BlueDash campaign that uses Microsoft Teams-themed phishing messages to target victims with "secure document" lures. The activity stands out because it does not rely on custom malware alone. Instead, it delivers legitimate remote monitoring and management tools that can be misused for unauthorized access.

According to the reported findings, the campaign uses fake Teams and Zoom updates as part of the infection chain. Those bogus updates are used to install Level RMM, ScreenConnect, and Tactical RMM, all of which are known remote administration products. By leaning on widely used software, the operators appear to blend malicious access with tools that may look familiar in business environments.

The use of several RMM platforms in one operation suggests an effort to keep multiple ways into a compromised system. Researchers described this as an apparent attempt to maintain redundant access, which can help an attacker stay connected even if one tool is detected or removed. That approach can also complicate incident response because defenders may need to identify and eliminate more than one remote access channel.

The campaign is another example of how phishing themes built around common workplace software continue to be effective. Fake collaboration app updates and document-related lures can pressure users into acting quickly, while legitimate administration utilities can make suspicious activity harder to spot. The case highlights the ongoing risk of trusted tools being repurposed in phishing-driven intrusions.