Bank of America Phishing Email Delivers ScreenConnect Malware
Cybersecurity Classified by Officially
We recently came across a fake Bank of America message that closely imitates the targeted bank's visual style, layout, and branding – from the initial phishing email, to the eventual webpage that victims are redirected to.
The subsequent phishing page delivers an AccountGuard.zip with a .vbs file that contains a large chunk of base64-encoded data. The next phase of the attack then involves a complex chain of decoding scripts, and ends in the execution of arbitrary commands (with escalated privileges) in PowerShell.
The goal of all this complexity is to download a Microsoft installer (.msi) for a custom ScreenConnect client and execute/install it with Administrator privileges without prompting the user for elevation. Additional payload components conceal the installed ScreenConnect client and remove the user's ability to uninstall or disable it easily.
As seen in this ongoing phishing campaign, threat actors continue to rely on tried-and-true stealth tactics, including the abuse of RMMs like ScreenConnect (and additional measures to hide this abuse), phishing attacks that closely mimic popular brands, and more. There are several measures defenders can take to avoid these types of techniques.
Acknowledgments: Huntress wishes to acknowledge the contributions of Andrew Schwartz of the DE&TH team for his efforts in tracking remote monitoring and management (RMM) tool abuse trends.
TL;DR: Huntress received an email sent to a honeytrap account that pretends to be from Bank of America. The email prompts the recipient to visit what it says is the bank's website. However, a link to the "Security Center" actually delivers a Visual Basic script that, when executed, begins a multi-stage chain of decoding complex content and leads to the download of a ScreenConnect installer.
Huntress received a message in a spamtrap email account on July 28 that appeared to originate from Bank of America: the email came from onlinebanking@ealerts[.]bkofamerica[.]com.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.huntress.com/blog/bank-spam-rmm
Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Huntress — imported from official source
- Official source
- https://www.huntress.com/blog/rss.xml RSS
- Imported
- September 20, 2026 19:55
- Versions
- 1 recorded
- Identity
https://www.huntress.com/blog/bank-spam-rmm