ScreenConnect remote access malware delivered through fake Bank of America phishing
Malware Activity
Summary
Hide ▲
Show ▼
A fake Bank of America phishing chain now delivers ScreenConnect RMM to Windows victims, creating remote access, privilege escalation, and C2 connectivity risk. The lure uses lookalike domains and a multi-stage script chain to install the payload and hide its presence. Once deployed, the tool connects to a suspected operator server and awaits commands.
Related Happenings
Fake Bank of America phishing remote-control campaign
Campaign
H score32
First: 05.08.2026 11:00
Last: 05.08.2026 11:00
Sources 1
How related:
A new phishing scam that presents a fake Bank of America message is being used by cybercriminals to gain remote control of victims’ users.
About this happening:
The fake Bank of America phishing campaign is delivering a multi-stage download chain that can install ScreenConnect and give attackers remote control of victim sy...
Fake Bank of America phishing remote-control campaign
CampaignHow related: A new phishing scam that presents a fake Bank of America message is being used by cybercriminals to gain remote control of victims’ users.
About this happening: The fake Bank of America phishing campaign is delivering a multi-stage download chain that can install ScreenConnect and give attackers remote control of victim sy...
KongTuke ClickFix and Teams access-seeking campaign
Campaign
H score33
First: 25.06.2026 11:54
Last: 25.06.2026 11:54
Sources 1
About this happening:
The KongTuke operation is using ClickFix lures and Microsoft Teams messages to widen access-seeking attacks against multiple organizations, increasing the risk of...
KongTuke ClickFix and Teams access-seeking campaign
CampaignAbout this happening: The KongTuke operation is using ClickFix lures and Microsoft Teams messages to widen access-seeking attacks against multiple organizations, increasing the risk of...
Google Ads tax-search ScreenConnect malvertising campaign
Campaign
H score32
First: 24.03.2026 19:05
Last: 24.03.2026 19:05
Sources 1
About this happening:
A malvertising campaign active since January 2026 is using Google Ads and tax-related search terms to push rogue ConnectWise ScreenConnect installers, creating a p...
Google Ads tax-search ScreenConnect malvertising campaign
CampaignAbout this happening: A malvertising campaign active since January 2026 is using Google Ads and tax-related search terms to push rogue ConnectWise ScreenConnect installers, creating a p...
Timeline
-
05.08.2026 11:00 1 articles · 1h ago
Fake Bank of America emails deliver Account Guard lure and ScreenConnect payload
Exploitation ObservedPhishing emails impersonating Bank of America were sent to the Huntress honeytrap account on July 28, steering Windows recipients through bkofamerica[.]com to kleinschnitg[.]com and sectioncompil[.]com, where a fake “Security Centre” page offered “Account Guard”, dropped AccountGuardSetup.zip and AccountGuardSetup.vbs, and led to ScreenConnect RMM installation on the target system.
Show sources
- Fake Bank of America Phishing Scam Installs Remote Access Malware — www.infosecurity-magazine.com — 05.08.2026 11:00
-
05.08.2026 11:00 2 articles · 1h ago
Huntress details the ScreenConnect loader chain and suspected C2 server
Technical Analysis UpdateHuntress analyzed the campaign on August 5, describing a multi-stage chain of Base64-decoded content, a C# script that invokes the ICMLuaUtil COM interface UAC bypass, a 17MB Base64-encoded installer from UploadToURL.com, and a ScreenConnect MSI package that masqueraded as “Windows Security” before connecting to 217.60.195[.]167 over TCP port 8041; the suspected C2 IP geolocates to the United Arab Emirates, and Huntress advised checking sender domains and link destinations.
Show sources
- Fake Bank of America Phishing Scam Installs Remote Access Malware — www.infosecurity-magazine.com — 05.08.2026 11:00
- Fake Bank of America Phishing Scam Installs Remote Access Malware — www.infosecurity-magazine.com — 05.08.2026 11:00