As cited
Copy frozen at (site build).
threat intel
Bank of America impersonators weaponize ScreenConnect, then make it hard to remove
Attackers are conducting a phishing campaign that impersonates Bank of America and tricks Windows users into installing ScreenConnect remote access software, which is designed to be difficult to remove. The emails cite account restrictions to create urgency and direct victims to a Bank of America lookalike site. Huntress researchers identified the campaign and noted that Mac and Windows users face different attack paths.
Why it matters: Bank of America customers and organizations managing Windows endpoints face credential theft and unauthorized remote access risk; practitioners should educate end users on phishing indicators and review email filtering rules for spoofed BoA domains.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Bank of America impersonators weaponize ScreenConnect, then make it hard to remove
Attackers are conducting a phishing campaign that impersonates Bank of America and tricks Windows users into installing ScreenConnect remote access software, which is designed to be difficult to remove. The emails cite account restrictions to create urgency and direct victims to a Bank of America lookalike site. Huntress researchers identified the campaign and noted that Mac and Windows users face different attack paths.
Why it matters: Bank of America customers and organizations managing Windows endpoints face credential theft and unauthorized remote access risk; practitioners should educate end users on phishing indicators and review email filtering rules for spoofed BoA domains.
- Source published
- First seen by Cybersecurity Tracker