Threats & Adversaries · Credential Theft
Trusted Remote-Admin Tools Become Stealth Persistence A fake bank lure is not the main danger here. The danger is that a legitimate ScreenConnect installer can leave behind remote access that looks like normal IT support, and Windows ACL changes make it harder to spot or remove.
Huntress says a Bank of America phishing email seen on July 28 delivered a Visual Basic script that led to a ScreenConnect installer. The report says the attacker used Windows SDDL ACLs to hide and persist the remote-access pieces on Windows endpoints.
If users can install remote-support tools, or if you already allow RMM software, the same trust path can be abused to keep quiet access inside the endpoint. A single malware cleanup may miss the real foothold if the tool itself now blends into admin traffic.
3 sources · Aug 5
Timeline Sources Aug 5 Help Net Security
Bank of America impersonators weaponize ScreenConnect, then make it hard to remove - Help Net Security
A phishing campaign impersonating Bank of America (BoA) is trying to trick Windows users into installing ScreenConnect remote access software.
original Aug 5 Infosecurity Magazine
Fake Bank of America Phishing Scam Installs Remote Access Malware
Cybercriminals are using a fake Bank of America phishing campaign to trick users into downloading a malicious script that installs ScreenConnect
original Aug 4 Huntress Blog
Bank of America Phishing Email Delivers ScreenConnect Malware | Huntress
A fake Bank of America phishing email kicks off a multi-stage malware infection chain.
original Part of the PlainSec briefing for 2026-08-06
Every edition of this story: Trusted Remote-Admin Tools Become Stealth Persistence
More from today
Threats & Adversaries · Credential Theft
Trusted Remote-Admin Tools Become Stealth Persistence A fake bank lure is not the main danger here. The danger is that a legitimate ScreenConnect installer can leave behind remote access that looks like normal IT support, and Windows ACL changes make it harder to spot or remove.
Huntress says a Bank of America phishing email seen on July 28 delivered a Visual Basic script that led to a ScreenConnect installer. The report says the attacker used Windows SDDL ACLs to hide and persist the remote-access pieces on Windows endpoints.
If users can install remote-support tools, or if you already allow RMM software, the same trust path can be abused to keep quiet access inside the endpoint. A single malware cleanup may miss the real foothold if the tool itself now blends into admin traffic.
3 sources · Aug 5
Timeline Sources Aug 5 Help Net Security
Bank of America impersonators weaponize ScreenConnect, then make it hard to remove - Help Net Security
A phishing campaign impersonating Bank of America (BoA) is trying to trick Windows users into installing ScreenConnect remote access software.
original Aug 5 Infosecurity Magazine
Fake Bank of America Phishing Scam Installs Remote Access Malware
Cybercriminals are using a fake Bank of America phishing campaign to trick users into downloading a malicious script that installs ScreenConnect
original Aug 4 Huntress Blog
Bank of America Phishing Email Delivers ScreenConnect Malware | Huntress
A fake Bank of America phishing email kicks off a multi-stage malware infection chain.
original Part of the PlainSec briefing for 2026-08-06
Every edition of this story: Trusted Remote-Admin Tools Become Stealth Persistence
More from today