Critical

Fake Bank of America Phishing Scam Installs Remote Access Malware

Infosecurity Magazine
Actively Exploited

Overview

Cybercriminals are running a phishing campaign disguised as Bank of America communications to deceive users into downloading a harmful script. This script installs ScreenConnect, a remote access tool that allows attackers to control infected systems. Victims of this scam may unknowingly give hackers persistent access to their devices, potentially leading to data theft or further exploitation. It's crucial for users to remain vigilant against such phishing attempts and verify the authenticity of any unexpected emails. This incident serves as a reminder that even well-known brands can be used as bait in cyber attacks.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Bank of America customers, users of infected systems
  • Action Required: Users should be cautious with unsolicited emails and verify the sender before downloading any attachments or clicking links.
  • Timeline: Newly disclosed

Original Article Summary

Cybercriminals are using a fake Bank of America phishing campaign to trick users into downloading a malicious script that installs ScreenConnect, enabling remote access and persistence on compromised systems

Impact

Bank of America customers, users of infected systems

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Users should be cautious with unsolicited emails and verify the sender before downloading any attachments or clicking links. Regularly updating security software and using multi-factor authentication can also help mitigate risks.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Phishing, Malware.

Related Coverage

When an Agent Fails: Incident Response for AI-Initiated Access Events

SCM feed for Latest

The article discusses the challenges faced by cybersecurity teams when responding to incidents initiated by artificial intelligence. It highlights how AI can create new vulnerabilities, leading to unauthorized access events that traditional security measures might miss. Businesses and organizations are advised to enhance their incident response strategies to account for these AI-driven scenarios, ensuring they can effectively detect and mitigate such threats. The focus is on developing a proactive approach to security that includes monitoring AI activities and implementing robust authentication processes. This is particularly important as AI continues to evolve and become more integrated into various systems.

Aug 23, 2026

UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks

Security Affairs

Iran-linked hackers successfully disabled a power plant in the UK for four days, marking a significant cyberattack on the country's energy sector. This incident is considered the first confirmed attack of its kind in the UK. The timing of the attack coincided with similar incidents targeting water infrastructure across 12 states in the United States, raising concerns about coordinated efforts by these hackers. The impact of such attacks on critical infrastructure is profound, as it not only disrupts services but also poses risks to public safety and national security. As countries increasingly rely on digital systems for essential services, the need for robust cybersecurity measures becomes even more urgent.

Aug 23, 2026

Security Affairs newsletter Round 591 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs

A new version of the malware known as ToxicPanda has been reported, now dubbed ToxicPanda 2.0. This upgraded malware is expanding its reach and has been detected in 16 different countries. Researchers have found that it specifically targets Android car head units, hijacking them for malicious purposes. This poses significant risks for drivers as it can compromise vehicle systems and potentially allow attackers to manipulate navigation and other functions. Users and manufacturers of affected devices need to be vigilant and implement security measures to protect against this evolving threat.

Aug 23, 2026

Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection

Security Affairs

Researchers at Adversa AI have developed a new attack method called Cryptographic Context Injection, which allows attackers to bypass safety controls in AI systems. This technique involves sending encrypted instructions as AES-encrypted payloads that trick the AI into decrypting them within its own execution environment. As a result, attackers can potentially access complete chat histories from Grok, a conversational AI platform. This poses a significant risk to user privacy, as sensitive information could be leaked without any user interaction required. The discovery raises concerns about the security of AI systems and the effectiveness of current safety measures designed to protect user data.

Aug 23, 2026

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

The Hacker News

TikTok has agreed to pay $400 million to settle a lawsuit filed by the U.S. Department of Justice, which accused the company of breaching child privacy laws. The lawsuit claimed that TikTok collected personal information from minors without proper consent, violating federal regulations aimed at protecting children's online privacy. As part of the settlement, TikTok will pay $300 million upfront and an additional $100 million once a previous court order is lifted. This case emphasizes ongoing concerns about how social media platforms handle user data, especially when it comes to minors. The settlement could lead to stricter compliance measures for TikTok and other companies in the industry regarding child privacy protections.

Aug 22, 2026

Named Pipes Under Attack: Securing Windows Interprocess Communication

BleepingComputer

Windows named pipes, a method for fast communication between processes, have been identified as a potential security risk due to weak access controls. This vulnerability allows untrusted processes to potentially access privileged services, posing a threat to system integrity. Security experts from ThreatLocker recommend several strategies to mitigate these risks, including endpoint verification, command authorization, strict input validation, and limiting privileges to what is necessary. These measures can help secure named-pipe communications and protect against unauthorized access. Organizations using Windows systems should take these recommendations seriously to safeguard their environments from potential exploitation.

Aug 22, 2026