Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

Fake Bank of America Phishing Emails Found Delivering Disguised ScreenConnect RAT via UAC Bypass

A phishing campaign spoofing Bank of America delivers ScreenConnect as a disguised RAT via UAC bypass, giving attackers persistent access that blends in with legitimate RMM traffic.

Summary written by editorial AI · Source link below

Filed by IT Security Guru1 min readRead at source ↗

Researchers at Huntress have identified an active phishing campaign impersonating Bank of America that culminates in the covert installation of a remote monitoring and management (RMM) tool, giving attackers persistent, hard-to-detect access to victims’ Windows machines. The campaign was flagged after a message landed in one of Huntress’s spamtrap accounts on 28 July, sent from […] The post Fake Bank of America Phishing Emails Found Delivering Disguised ScreenConnect RAT via UAC Bypass appeared

Editorial Analysis

Why it matters

Abuse of legitimate RMM tools like ScreenConnect for persistent access makes detection harder; enterprises must treat unauthorised RMM installations as high-priority indicators of compromise.

What to do

Implement application-whitelisting policies for RMM tools and monitor for unauthorised ScreenConnect deployments across endpoints.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at IT Security Guru

External link — opens at IT Security Guru in a new tab.

§
Continue with

More from the Threat Intel Desk