
ClickFix Trick Spreads ACR Stealer via Paste-Run
Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR…
Researchers reported a real phishing campaign (“Operation BlueDash”) that tricks users with a “secure document” lure and routes them to a fake Microsoft Store page that claims Microsoft Teams must be updated. The download installs legitimate remote access tools (Level RMM and ScreenConnect) so attackers can keep persistent access to the victim’s computer.
The campaign known as Operation BlueDash starts with a message claiming a secure document has been shared with the recipient. To open it, the message says, Microsoft Teams must first be updated. Clicking through leads to a counterfeit Microsoft Store page hosted on a look-alike domain rather than an official Microsoft property. The download that follows installs legitimate remote monitoring and management tools, including Level RMM and ScreenConnect, giving attackers persistent, redundant access to the victim's machine.
A related repository tied to the same infrastructure hosts a Zoom-themed variant. Instead of a document, the lure is a meeting invite that prompts installation of an additional component. That installer pulls down the Tactical RMM agent from its official GitHub release, installs it into a Windows temporary directory, and registers the compromised host with the attacker using an embedded authentication token. This shows a multi-brand approach where the core installer stays the same while the lure, hosting, and remote access tool are swapped out.
A separate but connected effort, JIVS PhishKit, skips software installation entirely. It sends emails claiming a mailbox has violated policy and directs recipients to a generic Session Expired page designed to harvest whatever corporate email password is entered, regardless of the platform behind it.
These lures work because they piggyback on routine workplace activity: opening a shared document, joining a meeting, or responding to an IT notice. Because the payloads are legitimate remote access software rather than obviously malicious files, they are less likely to trigger suspicion or basic security tooling. The Session Expired page is generic enough to look plausible against many corporate identity providers, not just one brand.
Employees across all roles, including executives, helpdesk staff, and IT administrators, should be trained to verify update prompts through official channels rather than links in messages. Encourage staff to check the actual domain behind any download page and to report unexpected installer prompts tied to meeting invites or shared documents. Reinforcing skepticism toward urgent mailbox policy warnings and unfamiliar login pages can reduce the chance that credentials or system access are handed over during one of these campaigns.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Operation BlueDash is a phishing campaign that uses a fake secure document lure to send victims to a counterfeit Microsoft Store page, which then installs legitimate remote monitoring and management tools like Level RMM and ScreenConnect for persistent access.
Victims receive a message about a shared secure document that cannot be opened until Microsoft Teams is updated. The link leads to a counterfeit Microsoft Store page hosted on the domain teamvem[.]com rather than an official Microsoft domain.
A related repository hosts a Zoom meeting lure that installs the Tactical RMM agent, and a separate kit called JIVS PhishKit uses fake mailbox policy violation emails and a generic Session Expired page to steal email passwords.
Watch for unexpected requests to install software before viewing a document, verify that update pages are on official vendor domains, and treat urgent policy violation emails that link to unfamiliar domains with caution.
You get an email: “Secure document shared with you in Teams, update required.” Looks normal, right? Click it, and you land on what looks like the Microsoft Store, saying you must update Teams to see the file. But check the address bar: it’s teamvem.com, not Microsoft. If you install that “update,” a file called supportdev.exe quietly drops real remote tools like Level RMM and ScreenConnect, giving someone persistent access to your computer. Here’s the move: if a document or meeting says you must install or update Teams or Zoom, stop. Don’t install, report it to IT or Security immediately.

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR…

ClickFix is a fast-growing social engineering tactic that gets people to run malware themselves by pasting a command into Windows Run or macOS Terminal.…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Researchers and a Windows app developer uncovered a campaign using lookalike “official” software download websites that rank highly in Google results. The…