Infosecurity-Magazine Bank of America Phishing Scam Installs ScreenConnect Malware
Article Content
- •Phishing emails impersonate Bank of America to deliver malware.
- •ScreenConnect malware is installed via a Visual Basic script from a malicious zip file.
- •Attack methods vary based on the victim's device type, targeting both Windows and Mac users.
A phishing email masquerading as a Bank of America message has been identified, targeting users to install ScreenConnect malware. The email, received by Huntress on July 28, prompts recipients to visit a fake website that mimics the bank's branding. Victims are redirected to a malicious page that delivers a Visual Basic script, leading to the installation of ScreenConnect, a remote access tool. The attack differentiates between device types, with Mac users directed to a phishing page for personal information, while Windows users are prompted to download a malicious zip file. The malware uses a UAC bypass to elevate privileges and connects to a command-and-control server located in the UAE. Huntress has advised users to be cautious of email origins and link destinations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Avaddon, Purple Fox Rootkit and Bank Of America in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…