Find notable cyber news and cases, enriched with sources, timelines, and signals.

ScreenConnect remote access malware delivered through fake Bank of America phishing

Malware Activity
First reported
Last updated
Happening score
H score 28
1 unique sources, 1 articles

Summary

Hide ▲

A fake Bank of America phishing chain now delivers ScreenConnect RMM to Windows victims, creating remote access, privilege escalation, and C2 connectivity risk. The lure uses lookalike domains and a multi-stage script chain to install the payload and hide its presence. Once deployed, the tool connects to a suspected operator server and awaits commands.

Related Happenings

Fake Bank of America phishing remote-control campaign

Campaign
H score32 First: 05.08.2026 11:00 Last: 05.08.2026 11:00 Sources 1

How related: A new phishing scam that presents a fake Bank of America message is being used by cybercriminals to gain remote control of victims’ users.

About this happening: The fake Bank of America phishing campaign is delivering a multi-stage download chain that can install ScreenConnect and give attackers remote control of victim sy...

KongTuke ClickFix and Teams access-seeking campaign

Campaign
H score33 First: 25.06.2026 11:54 Last: 25.06.2026 11:54 Sources 1

About this happening: The KongTuke operation is using ClickFix lures and Microsoft Teams messages to widen access-seeking attacks against multiple organizations, increasing the risk of...

Google Ads tax-search ScreenConnect malvertising campaign

Campaign
H score32 First: 24.03.2026 19:05 Last: 24.03.2026 19:05 Sources 1

About this happening: A malvertising campaign active since January 2026 is using Google Ads and tax-related search terms to push rogue ConnectWise ScreenConnect installers, creating a p...

Timeline

  1. 05.08.2026 11:00 1 articles · 1h ago

    Fake Bank of America emails deliver Account Guard lure and ScreenConnect payload

    Exploitation Observed

    Phishing emails impersonating Bank of America were sent to the Huntress honeytrap account on July 28, steering Windows recipients through bkofamerica[.]com to kleinschnitg[.]com and sectioncompil[.]com, where a fake “Security Centre” page offered “Account Guard”, dropped AccountGuardSetup.zip and AccountGuardSetup.vbs, and led to ScreenConnect RMM installation on the target system.

    Show sources
  2. 05.08.2026 11:00 2 articles · 1h ago

    Huntress details the ScreenConnect loader chain and suspected C2 server

    Technical Analysis Update

    Huntress analyzed the campaign on August 5, describing a multi-stage chain of Base64-decoded content, a C# script that invokes the ICMLuaUtil COM interface UAC bypass, a 17MB Base64-encoded installer from UploadToURL.com, and a ScreenConnect MSI package that masqueraded as “Windows Security” before connecting to 217.60.195[.]167 over TCP port 8041; the suspected C2 IP geolocates to the United Arab Emirates, and Huntress advised checking sender domains and link destinations.

    Show sources