Fake Bank of America Phishing Emails Found Delivering Disguised ScreenConnect RAT via UAC Bypass
A phishing campaign spoofing Bank of America delivers ScreenConnect as a disguised RAT via UAC bypass, giving attackers persistent access that blends in with legitimate RMM traffic.
Summary written by editorial AI · Source link below
Researchers at Huntress have identified an active phishing campaign impersonating Bank of America that culminates in the covert installation of a remote monitoring and management (RMM) tool, giving attackers persistent, hard-to-detect access to victims’ Windows machines. The campaign was flagged after a message landed in one of Huntress’s spamtrap accounts on 28 July, sent from […] The post Fake Bank of America Phishing Emails Found Delivering Disguised ScreenConnect RAT via UAC Bypass appeared
Editorial Analysis
Abuse of legitimate RMM tools like ScreenConnect for persistent access makes detection harder; enterprises must treat unauthorised RMM installations as high-priority indicators of compromise.
Implement application-whitelisting policies for RMM tools and monitor for unauthorised ScreenConnect deployments across endpoints.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at IT Security Guru in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner2d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d