📋 Top Headlines at a Glance

  1. Fake Bank of America Phishing Scam Installs Remote Access Malware
  2. Cloudflare gives AI agents wallets with built-in spending controls
  3. Water Sector Cyberattacks Reportedly Hit at Least 12 States
  4. SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access
  5. QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

Executive Summary: Today’s intelligence highlights a concerning surge in the abuse of legitimate remote access tools, primarily ScreenConnect, through sophisticated social engineering campaigns like phishing and fake software updates. This trend is compounded by a long-standing supply chain attack targeting a VPN service and confirmed cyberattacks against critical water sector infrastructure across multiple U.S. states. Simultaneously, new developments in AI agent security, such as Cloudflare’s controlled wallets, signal an evolving landscape for digital transactions and potential new attack surfaces. The overarching theme is the persistent effectiveness of social engineering combined with advanced persistent threats against both end-users and critical services.

🌍 Technical Intelligence Breakdown

🎣 Fake Bank of America Phishing Scam Installs Remote Access Malware

Cybercriminals are leveraging a deceptive phishing campaign impersonating Bank of America. This campaign aims to trick users into downloading a malicious script.

  • Attack Vector: Phishing emails impersonating a financial institution.
  • Payload Delivery: Malicious script download.
  • Malware Installed: ScreenConnect, a legitimate remote access tool.
  • Impact: Establishes remote access and persistence on compromised systems.
  • Defensive Actions:
    • Enhance email security gateways to detect and block phishing attempts.
    • Implement robust endpoint detection and response (EDR) solutions to identify suspicious script execution and ScreenConnect installations.
    • Conduct regular security awareness training for employees, emphasizing vigilance against financial phishing lures.

🤖 Cloudflare gives AI agents wallets with built-in spending controls

Cloudflare is introducing “Wallets” for AI agents operating on its platform, designed to facilitate payments for APIs and online content. These wallets will feature creator-defined spending limits.

  • New Capability: AI agents can now possess “human-readable wallet handles” for transactions.
  • Security Feature: Built-in spending controls and limits set by the creator.
  • Wallet Types: Account Wallets for organizations and Virtual Wallets for specific AI agents.
  • Availability: Handle reservations are open, with service rollout expected in the coming months.
  • Implications: While enhancing AI agent functionality, this introduces new considerations for financial security and access control within AI ecosystems. Organizations deploying AI agents should carefully configure spending limits and monitor transaction logs.

💧 Water Sector Cyberattacks Reportedly Hit at Least 12 States

Cyberattacks have reportedly impacted the water sector in at least 12 U.S. states. Georgia has confirmed an incident involving a pump station disruption in Clayton County.

  • Target Sector: Critical infrastructure, specifically the water sector.
  • Geographic Scope: At least 12 states affected, with Georgia confirmed.
  • Confirmed Impact: Disruption of a pump station in Clayton County, Georgia.
  • Attack Details: Dataset provides limited detail regarding the specific attack vectors, threat actors, or malware involved.
  • Defensive Actions:
    • Implement strong network segmentation between IT and Operational Technology (OT) environments.
    • Conduct regular vulnerability assessments and penetration testing of OT/ICS systems.
    • Develop and test comprehensive incident response plans tailored for critical infrastructure disruptions.
    • Enhance threat intelligence sharing within the water sector to proactively address emerging threats.

🎭 SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access

The SMOKE#SCREEN campaign is actively abusing ConnectWise ScreenConnect RMM to gain persistent remote access. This multi-wave campaign employs various social engineering lures.

  • Campaign Name: SMOKE#SCREEN.
  • Primary Tool Abused: ConnectWise ScreenConnect RMM.
  • Attack Vector: Social engineering, including:
    • Fake Zoom updates.
    • Adobe software notices.
    • Business document reviews.
    • System maintenance utilities.
  • Objective: Install ScreenConnect to achieve persistent remote access and bypass defenses.
  • Threat Actor: Unknown.
  • Defensive Actions:
    • Implement application whitelisting to prevent unauthorized software installation.
    • Educate users on identifying and reporting social engineering attempts, especially those involving software updates or urgent document reviews.
    • Monitor for unusual ScreenConnect installations or connections, particularly from unexpected sources.
    • Enforce multi-factor authentication (MFA) for all remote access solutions.

⛓️ QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

A “long-standing supply chain attack” has been disclosed, targeting QuickFox, a VPN and network acceleration tool. The attack involves a trojanized Windows installer delivering the FDMTP backdoor.

  • Attack Type: Supply chain attack.
  • Target Software: QuickFox VPN and network acceleration tool.
  • Delivery Mechanism: Trojanized Windows installer for the QuickFox application.
  • Malware Payload: FDMTP backdoor.
  • Duration: Active since at least August 2025.
  • Impact: Compromised users installing the trojanized software will have the FDMTP backdoor installed, granting attackers unauthorized access.
  • Defensive Actions:
    • Implement strict software supply chain security practices, including validating software integrity (e.g., hash checking, digital signatures).
    • Advise users to download software only from official, verified sources.
    • Utilize endpoint security solutions capable of detecting known backdoors and suspicious installer behavior.
    • Implement network segmentation to limit the lateral movement potential of compromised systems.

📉 Threat Landscape & Trends

The current threat landscape is characterized by a dual focus on human exploitation and infrastructure compromise. Social engineering, particularly through phishing and deceptive software updates, remains a highly effective initial access vector, leading to the abuse of legitimate remote access tools like ScreenConnect. This highlights a persistent challenge in user awareness and endpoint security. Concurrently, sophisticated supply chain attacks continue to pose a long-term risk, as evidenced by the QuickFox compromise, demonstrating attackers’ willingness to invest in stealthy, persistent access. The confirmed attacks on the water sector underscore the critical and ongoing threat to national infrastructure, demanding robust OT/ICS security measures. The introduction of AI agent wallets, while a functional advancement, also signals the emergence of new digital assets and transaction flows that will inevitably become targets for future cyber threats.

📌 Strategic Takeaway

Organizations must fortify their defenses against social engineering and supply chain risks by implementing multi-layered security controls, enhancing user education, and rigorously validating software integrity. Simultaneously, critical infrastructure operators must prioritize the segmentation and hardening of OT/ICS environments against targeted attacks, while all sectors prepare for the security implications of emerging technologies like AI agents.


🔗 References

  1. Fake Bank of America Phishing Scam Installs Remote Access Malware
  2. Cloudflare gives AI agents wallets with built-in spending controls
  3. Water Sector Cyberattacks Reportedly Hit at Least 12 States
  4. SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access
  5. QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer