Skip to content
Bank of America Phishing Scam Installs ScreenConnect Malware

Bank of America Phishing Scam Installs ScreenConnect Malware

First seen 5 Aug 2026, 08:48 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 6, 2026 at 07:23 UTC

A phishing email masquerading as a Bank of America message has been identified, targeting users to install ScreenConnect malware. The email, received by Huntress on July 28, prompts recipients to visit a fake website that mimics the bank's branding. Victims are redirected to a malicious page that delivers a Visual Basic script, leading to the installation of ScreenConnect, a remote access tool. The attack differentiates between device types, with Mac users directed to a phishing page for personal information, while Windows users are prompted to download a malicious zip file. The malware uses a UAC bypass to elevate privileges and connects to a command-and-control server located in the UAE. Huntress has advised users to be cautious of email origins and link destinations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 46d ago How this analysis works

Timeline

2026-07-28
Phishing emails sent to Huntress honeytrap
Emails disguised as Bank of America messages were sent, prompting users to visit a fake website.
Huntress
2026-08-04
Huntress publishes findings on phishing scam
Huntress details the phishing attack and its methods, including the installation of ScreenConnect malware.
Huntress
2026-08-05
Infosecurity Magazine reports on the phishing scam
Infosecurity Magazine highlights the phishing scam identified by Huntress, detailing the attack's execution.
Infosecurity-Magazine

More articles in this cluster (6)

Following this threat?

Track Avaddon, Purple Fox Rootkit and Bank Of America in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed