Infosecurity-Magazine
Bank of America Phishing Scam Installs ScreenConnect Malware
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A phishing email masquerading as a Bank of America message has been identified, targeting users to install ScreenConnect malware. The email, received by Huntress on July 28, prompts recipients to visit a fake website that mimics the bank's branding. Victims are redirected to a malicious page that delivers a Visual Basic script, leading to the installation of ScreenConnect, a remote access tool. The attack differentiates between device types, with Mac users directed to a phishing page for personal information, while Windows users are prompted to download a malicious zip file. The malware uses a UAC bypass to elevate privileges and connects to a command-and-control server located in the UAE. Huntress has advised users to be cautious of email origins and link destinations.
Key Points: • Phishing emails impersonate Bank of America to deliver malware. • ScreenConnect malware is installed via a Visual Basic script from a malicious zip file. • Attack methods vary based on the victim's device type, targeting both Windows and Mac users.