Find notable cyber news and cases, enriched with sources, timelines, and signals.

Fake Bank of America phishing remote-control campaign

Campaign
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

The fake Bank of America phishing campaign is delivering a multi-stage download chain that can install ScreenConnect and give attackers remote control of victim systems. The lure uses brand impersonation and device-specific pages to push Windows users into downloading a malicious archive while Mac users are prompted for personal information. The operation was observed in a July 28 sample and remains dangerous because the chain hides its payload through multiple redirect and script stages.

Related Happenings

ScreenConnect remote access malware delivered through fake Bank of America phishing

Malware Activity
H score28 First: 05.08.2026 11:00 Last: 05.08.2026 11:00 Sources 1

How related: Running the .vbs file leads to the installation of the ScreenConnect RMM on the target system.

About this happening: A fake Bank of America phishing chain now delivers ScreenConnect RMM to Windows victims, creating remote access, privilege escalation, and C2 connectivity risk...

Google DoubleClick malspam campaign delivering DesckVB RAT

Campaign
H score33 First: 03.06.2026 19:29 Last: 03.06.2026 19:29 Sources 1

About this happening: A new malspam campaign is abusing Google's DoubleClick redirect path to evade detection and deliver DesckVB RAT, putting users and organizations at risk of malware inf...

Timeline

  1. 05.08.2026 11:00 1 articles · 1h ago

    Fake Bank of America phishing email reaches a Huntress honeytrap account

    Initial Disclosure

    Cybercriminals send a fake Bank of America phishing email to a Huntress honeytrap account on July 28, using the bank's visual style and lookalike domains such as bkofamerica[.]com, kleinschnitg[.]com, and sectioncompil[.]com to steer recipients toward a spoofed banking page.

    Show sources
  2. 05.08.2026 11:00 2 articles · 1h ago

    Windows targets receive Account Guard lure and ScreenConnect installer chain

    Exploitation Observed

    A Windows target that clicks "Update My Information" is sent AccountGuardSetup.zip, which contains AccountGuardSetup.vbs; the chain decodes large Base64 blobs, installs ScreenConnect RMM, and uses a C# script that invokes the ICMLuaUtil COM interface UAC bypass, while Mac users are instead pushed to submit personal information.

    Show sources
  3. 05.08.2026 11:00 1 articles · 1h ago

    ScreenConnect hides as Windows Security and connects to a UAE-linked command server

    Victim Impact Update

    After installation, ScreenConnect disguises itself as a service called "Windows Security", removes installation traces, hides related files and services using Windows permissions, prevents normal uninstallation, and connects to 217.60.195[.]167 over TCP port 8041 to await operator commands; the server geolocates to the United Arab Emirates.

    Show sources