Bank of America Phishing Scam Installs ScreenConnect Malware

Bank of America Phishing Scam Installs ScreenConnect Malware

First seen 5 Aug 2026, 08:48 UTC HuntressInfosecurity-Magazinecyberbuff.github.iowww.sans.orggithub.com+1 93% similarity 69.5

Article Content

Browse articles
ThreatCluster

A phishing email masquerading as a Bank of America message has been identified, targeting users to install ScreenConnect malware. The email, received by Huntress on July 28, prompts recipients to visit a fake website that mimics the bank's branding. Victims are redirected to a malicious page that delivers a Visual Basic script, leading to the installation of ScreenConnect, a remote access tool. The attack differentiates between device types, with Mac users directed to a phishing page for personal information, while Windows users are prompted to download a malicious zip file. The malware uses a UAC bypass to elevate privileges and connects to a command-and-control server located in the UAE. Huntress has advised users to be cautious of email origins and link destinations.

Key Points: • Phishing emails impersonate Bank of America to deliver malware. • ScreenConnect malware is installed via a Visual Basic script from a malicious zip file. • Attack methods vary based on the victim's device type, targeting both Windows and Mac users.

ThreatCluster AI How this analysis works

Timeline

2026-07-28
Phishing emails sent to Huntress honeytrap
Emails disguised as Bank of America messages were sent, prompting users to visit a fake website.
Huntress
2026-08-04
Huntress publishes findings on phishing scam
Huntress details the phishing attack and its methods, including the installation of ScreenConnect malware.
Huntress
2026-08-05
Infosecurity Magazine reports on the phishing scam
Infosecurity Magazine highlights the phishing scam identified by Huntress, detailing the attack's execution.
Infosecurity-Magazine

Community

Browse all →

Tracked Entities in This Story