Fake Bank of America Phishing Emails Found Delivering Disguised ScreenConnect RAT via UAC Bypass
Brief
Researchers at Huntress have identified an active phishing campaign impersonating Bank of America that culminates in the covert installation of a remote monitoring and management (RMM) tool, giving attackers persistent, hard-to-detect access to victims’ Windows machines.
The campaign was flagged after a message landed in one of Huntress’s spamtrap accounts on 28 July, sent from a spoofed address designed to resemble a legitimate Bank of America domain. The email uses a familiar social-engineering hook: a time-limited warning urging the recipient to “confirm” their account details or risk restrictions being placed on it.
Device-dependent payloads
According to Huntress’s analysis, the phishing infrastructure fingerprints the visiting device and serves different content accordingly.
