Bank of America Phishing Scam Deploys Remote Access Malware

▼ Summary
– Cybercriminals are running a fake Bank of America phishing campaign to deceive users.
– The campaign tricks victims into downloading a malicious script.
– The script installs ScreenConnect, a remote access tool.
– ScreenConnect enables remote access and persistence on compromised systems.
Cybercriminals have launched a deceptive phishing operation targeting Bank of America customers, luring them into executing a malicious script that delivers ScreenConnect, a legitimate remote access tool repurposed for unauthorized control and long-term system persistence.
The campaign begins with fraudulent emails designed to mimic official Bank of America communications, often featuring urgent language about account suspensions, unauthorized transactions, or security verification requests. Victims who click embedded links are directed to counterfeit login pages that harvest credentials before triggering the malware download.
Once the script executes, it silently installs ScreenConnect, which grants attackers full remote control over the infected machine. This access allows threat actors to navigate files, capture keystrokes, extract sensitive data, and maintain a foothold for future intrusions. The use of a widely recognized tool like ScreenConnect helps the malware evade detection, as it appears as legitimate software to many security solutions.
Security researchers note that this tactic reflects a broader trend among cybercriminals, who increasingly abuse trusted remote access platforms to bypass traditional defenses. The persistence mechanisms embedded in the attack ensure that even if the initial infection is discovered, the attackers can regain access unless thorough cleanup is performed.
Bank of America has issued alerts reminding customers that they will never request passwords, PINs, or remote access to devices via email or unsolicited calls. Users are advised to verify any suspicious correspondence by contacting the bank directly through official channels, avoiding links in unexpected messages, and maintaining updated antivirus software.
For organizations, the campaign underscores the importance of restricting remote access tools through application allowlisting and monitoring for unusual ScreenConnect activity. Individuals who suspect compromise should disconnect affected devices from the network immediately, run a full system scan, and change all online account credentials from a clean device.
(Source: Infosecurity Magazine)




