Bank of America scams use ScreenConnect to hijack PCs

▼ Summary
– A phishing campaign impersonating Bank of America targets Windows users to install ScreenConnect remote access software.
– The campaign uses different traps for Mac and Windows users to increase effectiveness.
– The malware is designed to be difficult to uninstall after installation.
A new phishing wave is targeting Bank of America customers, with attackers specifically aiming to hijack Windows PCs by pushing a remote access tool called ScreenConnect. The campaign is designed to make the software stubbornly difficult to remove once it lands on a system, giving scammers a persistent foothold.
The scheme uses distinct lures depending on the victim’s platform. For Windows users, the attack begins with a fraudulent message that claims the recipient’s account has been locked or flagged for suspicious activity. The message urges the user to click a link to verify their identity or restore access. That link leads to a page that prompts the download of ScreenConnect, a legitimate remote support application that cybercriminals have repurposed for malicious ends.
Once installed, the software grants the attacker full control over the machine, allowing them to navigate files, capture credentials, or initiate fraudulent transactions. What makes this campaign particularly nasty is the uninstall process. The attackers configure the software in a way that hides its presence, disables standard removal methods, and even blocks attempts to terminate the associated processes. Victims often find that simply deleting the program from the Control Panel fails, leaving them stuck with an unwanted backdoor.
Mac users are not the primary target here, but the campaign includes a separate trap for them as well. In that variant, the phishing email directs users to a fake BoA portal that requests sensitive information such as online banking credentials and Social Security numbers. While the Mac attack does not rely on ScreenConnect, it still poses a serious risk of identity theft and account compromise.
Security researchers note that the phishing emails are crafted to look highly convincing, complete with official Bank of America logos, realistic sender addresses, and urgency-driven language. The goal is to bypass the user’s initial skepticism and get them to act quickly, before they have time to scrutinize the request.
For anyone who suspects they have been targeted, the first step is to disconnect the machine from the internet immediately. Next, use a trusted antivirus or anti-malware tool to scan and attempt removal. If the software resists deletion, booting the system in Safe Mode and manually removing the ScreenConnect files and registry entries may be necessary. In more stubborn cases, a full system restore or professional cleanup might be the only safe route.
Bank of America has issued reminders that it will never ask customers to install remote access software or request passwords through unsolicited links. Users should verify any account alert by navigating directly to the official BoA website or calling the number on the back of their card. Staying cautious and avoiding unsolicited downloads remains the strongest defense against this type of takeover.
(Source: Help Net Security)




