Trusted Remote-Admin Tools Become Stealth Persistence
A fake bank lure is not the main danger here. The danger is that a legitimate ScreenConnect installer can leave behind remote access that looks like normal IT support, and Windows ACL changes make it harder to spot or remove.
Huntress says a Bank of America phishing email seen on July 28 delivered a Visual Basic script that led to a ScreenConnect installer. The report says the attacker used Windows SDDL ACLs to hide and persist the remote-access pieces on Windows endpoints.
If users can install remote-support tools, or if you already allow RMM software, the same trust path can be abused to keep quiet access inside the endpoint. A single malware cleanup may miss the real foothold if the tool itself now blends into admin traffic.