CYBERSECURITYTRACKER
TRACKING7,159 stories in this site build1,507 vulnerability news stories in this site build
Permanent story citation

Bank of America impersonators weaponize ScreenConnect, then make it hard to remove

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3880

As cited

Copy frozen at (site build).

threat intel

Bank of America impersonators weaponize ScreenConnect, then make it hard to remove

Attackers are conducting a phishing campaign that impersonates Bank of America and tricks Windows users into installing ScreenConnect remote access software, which is designed to be difficult to remove. The emails cite account restrictions to create urgency and direct victims to a Bank of America lookalike site. Huntress researchers identified the campaign and noted that Mac and Windows users face different attack paths.

Why it matters: Bank of America customers and organizations managing Windows endpoints face credential theft and unauthorized remote access risk; practitioners should educate end users on phishing indicators and review email filtering rules for spoofed BoA domains.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Bank of America impersonators weaponize ScreenConnect, then make it hard to remove

Attackers are conducting a phishing campaign that impersonates Bank of America and tricks Windows users into installing ScreenConnect remote access software, which is designed to be difficult to remove. The emails cite account restrictions to create urgency and direct victims to a Bank of America lookalike site. Huntress researchers identified the campaign and noted that Mac and Windows users face different attack paths.

Why it matters: Bank of America customers and organizations managing Windows endpoints face credential theft and unauthorized remote access risk; practitioners should educate end users on phishing indicators and review email filtering rules for spoofed BoA domains.

VendorsMicrosoftConnectWise
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary