Threats · 54 days ago
A fake bank lure is not the main danger here. The danger is that a legitimate ScreenConnect installer can leave behind remote access that looks like normal IT support, and Windows ACL changes make it harder to spot or remove.
Huntress says a Bank of America phishing email seen on July 28 delivered a Visual Basic script that led to a ScreenConnect installer. The report says the attacker used Windows SDDL ACLs to hide and persist the remote-access pieces on Windows endpoints.
If users can install remote-support tools, or if you already allow RMM software, the same trust path can be abused to keep quiet access inside the endpoint. A single malware cleanup may miss the real foothold if the tool itself now blends into admin traffic.
3 sources covering this story
A phishing campaign impersonating Bank of America (BoA) is trying to trick Windows users into installing ScreenConnect remote access software.
Fake Bank of America Phishing Scam Installs Remote Access Malware
Cybercriminals are using a fake Bank of America phishing campaign to trick users into downloading a malicious script that installs ScreenConnect
Bank of America Phishing Email Delivers ScreenConnect Malware | Huntress
A fake Bank of America phishing email kicks off a multi-stage malware infection chain.
Part of the PlainSec briefing for 2026-08-06