MalwareAug 4, 2026
Fake Bank of America Phishing Emails Found Delivering Disguised ScreenConnect RAT via UAC Bypass
Fake Bank of America phishing emails deliver ScreenConnect RAT via UAC bypass to Windows machines.
Summary
Huntress researchers discovered an active phishing campaign impersonating Bank of America that delivers a disguised ScreenConnect remote access trojan (RAT) to Windows systems. The malware leverages a UAC bypass technique to gain persistent, covert access to compromised machines. The campaign was identified after a malicious email was captured in Huntress's spamtrap on July 28.
Indicators of Compromise
- malware — ScreenConnect RAT
Entities
Bank of America (vendor)Huntress (vendor)ScreenConnect (product)UAC bypass (technology)Windows (technology)